Samirbous
ca7a148f5a
[New rule] Remote Computer Account DnsHostName Update ( #1962 )
...
* [New rule] Remote Computer Account DnsHostName Update
Identifies remote update to a computer account DnsHostName attribute, if the new value is set a valid domain controller DNS hostname and the subject computer name is not a domain controller then it's high likely a preparation step to exploit CVE-2022-26923 in an attempt to elevate privileges from a standard domain user to domain admin privileges :
* added MS ref url
* Update rules/windows/privilege_escalation_suspicious_dnshostname_update.toml
Co-authored-by: Jonhnathan <jonhnathancesar@gmail.com >
* Update rules/windows/privilege_escalation_suspicious_dnshostname_update.toml
Co-authored-by: Jonhnathan <jonhnathancesar@gmail.com >
Co-authored-by: Jonhnathan <jonhnathancesar@gmail.com >
(cherry picked from commit 19ff825a91 )
2022-05-11 17:42:44 +00:00
..
2022-04-01 23:28:54 +00:00
2022-03-31 14:31:43 +00:00
2022-03-31 14:31:43 +00:00
2022-03-30 17:46:02 +00:00
2022-04-01 23:28:54 +00:00
2022-03-30 17:46:02 +00:00
2022-03-30 17:46:02 +00:00
2022-03-30 17:46:02 +00:00
2022-04-01 23:28:54 +00:00
2022-03-29 21:03:35 -04:00
2022-04-14 00:55:20 +00:00
2022-04-14 00:55:20 +00:00
2022-04-14 00:55:20 +00:00
2022-04-14 00:55:20 +00:00
2022-04-14 00:55:20 +00:00
2022-04-14 00:55:20 +00:00
2022-04-14 00:55:20 +00:00
2022-04-14 00:55:20 +00:00
2022-04-01 23:28:54 +00:00
2022-04-01 23:28:54 +00:00
2022-04-01 23:28:54 +00:00
2022-04-13 01:07:09 +00:00
2022-04-26 20:59:20 +00:00
2022-04-26 20:59:20 +00:00
2022-04-13 00:00:52 +00:00
2022-04-01 23:28:54 +00:00
2022-04-01 23:28:54 +00:00
2022-04-13 00:00:52 +00:00
2022-04-13 16:13:27 -04:00
2022-04-13 01:07:09 +00:00
2022-04-13 00:00:52 +00:00
2022-04-13 01:07:09 +00:00
2022-04-01 23:28:54 +00:00
2022-05-06 17:23:22 +00:00
2022-03-29 21:03:35 -04:00
2022-03-31 14:31:43 +00:00
2022-03-29 21:03:35 -04:00
2022-04-01 23:28:54 +00:00
2022-05-06 19:09:27 +00:00
2022-05-06 17:23:22 +00:00
2022-04-26 20:59:20 +00:00
2022-04-14 12:27:47 +00:00
2022-04-14 12:27:47 +00:00
2022-05-06 17:23:22 +00:00
2022-04-01 23:28:54 +00:00
2022-04-01 23:28:54 +00:00
2022-03-29 21:03:35 -04:00
2022-05-06 17:23:22 +00:00
2022-04-13 01:07:09 +00:00
2022-04-01 23:28:54 +00:00
2022-04-13 16:13:27 -04:00
2022-04-01 23:28:54 +00:00
2022-04-26 20:59:20 +00:00
2022-04-01 23:28:54 +00:00
2022-04-14 12:27:47 +00:00
2022-04-01 23:28:54 +00:00
2022-04-01 23:28:54 +00:00
2022-03-29 21:03:35 -04:00
2022-04-01 23:28:54 +00:00
2022-04-14 00:55:20 +00:00
2022-04-01 23:28:54 +00:00
2022-04-13 00:00:52 +00:00
2022-04-13 00:00:52 +00:00
2022-04-01 23:28:54 +00:00
2022-04-01 23:28:54 +00:00
2022-04-01 23:28:54 +00:00
2022-04-01 23:28:54 +00:00
2022-04-13 00:00:52 +00:00
2022-04-01 23:28:54 +00:00
2022-04-01 23:28:54 +00:00
2022-04-13 16:13:27 -04:00
2022-04-01 23:28:54 +00:00
2022-04-01 23:28:54 +00:00
2022-04-01 23:28:54 +00:00
2022-04-01 23:28:54 +00:00
2022-04-01 23:28:54 +00:00
2022-04-01 23:28:54 +00:00
2022-04-01 23:28:54 +00:00
2022-04-01 23:28:54 +00:00
2022-03-29 21:03:35 -04:00
2022-04-01 23:28:54 +00:00
2022-03-29 21:03:35 -04:00
2022-03-29 21:03:35 -04:00
2022-04-01 23:28:54 +00:00
2022-04-01 23:28:54 +00:00
2022-04-01 23:28:54 +00:00
2022-04-01 23:28:54 +00:00
2022-03-29 21:03:35 -04:00
2022-04-01 23:28:54 +00:00
2022-03-29 21:03:35 -04:00
2022-04-01 23:28:54 +00:00
2022-03-29 21:03:35 -04:00
2022-03-29 21:03:35 -04:00
2022-03-29 21:03:35 -04:00
2022-03-29 21:03:35 -04:00
2022-03-29 21:03:35 -04:00
2022-03-29 21:03:35 -04:00
2022-03-29 21:03:35 -04:00
2022-03-29 21:03:35 -04:00
2022-03-29 21:03:35 -04:00
2022-03-31 14:31:43 +00:00
2022-03-29 21:03:35 -04:00
2022-04-01 23:28:54 +00:00
2022-03-29 21:03:35 -04:00
2022-03-29 21:03:35 -04:00
2022-04-01 23:28:54 +00:00
2022-04-01 23:28:54 +00:00
2022-03-29 21:03:35 -04:00
2022-04-01 23:28:54 +00:00
2022-04-13 16:13:27 -04:00
2022-04-01 23:28:54 +00:00
2022-04-01 23:28:54 +00:00
2022-04-01 23:28:54 +00:00
2022-04-01 23:28:54 +00:00
2022-03-29 21:03:35 -04:00
2022-03-29 21:03:35 -04:00
2022-04-01 23:28:54 +00:00
2022-04-01 23:28:54 +00:00
2022-04-01 23:28:54 +00:00
2022-04-01 23:28:54 +00:00
2022-04-01 23:28:54 +00:00
2022-03-29 21:03:35 -04:00
2022-03-29 21:03:35 -04:00
2022-04-01 23:28:54 +00:00
2022-04-01 23:28:54 +00:00
2022-04-01 23:28:54 +00:00
2022-05-06 17:23:22 +00:00
2022-04-13 01:07:09 +00:00
2022-04-01 23:28:54 +00:00
2022-04-01 23:28:54 +00:00
2022-04-11 18:05:59 +00:00
2022-04-01 23:28:54 +00:00
2022-04-01 23:28:54 +00:00
2022-03-31 14:31:43 +00:00
2022-03-29 21:03:35 -04:00
2022-04-14 12:27:47 +00:00
2022-04-01 23:28:54 +00:00
2022-04-01 23:28:54 +00:00
2022-04-01 23:28:54 +00:00
2022-04-26 20:59:20 +00:00
2022-04-26 20:59:20 +00:00
2022-04-01 23:28:54 +00:00
2022-03-29 21:03:35 -04:00
2022-04-13 16:13:27 -04:00
2022-04-01 23:28:54 +00:00
2022-04-01 23:28:54 +00:00
2022-03-29 21:03:35 -04:00
2022-03-29 21:03:35 -04:00
2022-04-01 23:28:54 +00:00
2022-04-01 23:28:54 +00:00
2022-04-01 23:28:54 +00:00
2022-03-29 21:03:35 -04:00
2022-03-29 21:03:35 -04:00
2022-03-29 21:03:35 -04:00
2022-03-31 14:31:43 +00:00
2022-03-31 14:31:43 +00:00
2022-03-29 21:03:35 -04:00
2022-04-05 19:35:15 +00:00
2022-03-29 21:03:35 -04:00
2022-04-01 23:28:54 +00:00
2022-04-01 23:28:54 +00:00
2022-04-01 23:28:54 +00:00
2022-04-01 23:28:54 +00:00
2022-04-01 23:28:54 +00:00
2022-04-01 23:28:54 +00:00
2022-04-01 23:28:54 +00:00
2022-04-01 23:28:54 +00:00
2022-04-01 23:28:54 +00:00
2022-04-01 23:28:54 +00:00
2022-04-01 23:28:54 +00:00
2022-04-14 00:55:20 +00:00
2022-04-14 00:55:20 +00:00
2022-04-14 00:55:20 +00:00
2022-04-01 23:28:54 +00:00
2022-04-01 23:28:54 +00:00
2022-04-01 23:28:54 +00:00
2022-04-10 18:38:57 +00:00
2022-03-29 21:03:35 -04:00
2022-04-01 23:28:54 +00:00
2022-04-01 23:28:54 +00:00
2022-04-01 23:28:54 +00:00
2022-04-01 23:28:54 +00:00
2022-04-01 23:28:54 +00:00
2022-04-01 23:28:54 +00:00
2022-04-01 23:28:54 +00:00
2022-04-01 23:28:54 +00:00
2022-03-29 21:03:35 -04:00
2022-03-29 21:03:35 -04:00
2022-03-29 21:03:35 -04:00
2022-03-29 21:03:35 -04:00
2022-03-29 21:03:35 -04:00
2022-03-29 21:03:35 -04:00
2022-04-13 01:07:09 +00:00
2022-04-01 23:28:54 +00:00
2022-03-29 21:03:35 -04:00
2022-04-01 23:28:54 +00:00
2022-03-29 21:03:35 -04:00
2022-03-29 21:03:35 -04:00
2022-03-29 21:03:35 -04:00
2022-04-01 23:28:54 +00:00
2022-03-29 21:03:35 -04:00
2022-04-13 00:00:52 +00:00
2022-03-29 21:03:35 -04:00
2022-04-01 23:28:54 +00:00
2022-03-29 21:03:35 -04:00
2022-04-13 01:07:09 +00:00
2022-04-01 23:28:54 +00:00
2022-04-01 23:28:54 +00:00
2022-04-01 23:28:54 +00:00
2022-04-14 12:27:47 +00:00
2022-04-14 00:55:20 +00:00
2022-03-29 21:03:35 -04:00
2022-04-01 23:28:54 +00:00
2022-04-01 23:28:54 +00:00
2022-03-29 21:03:35 -04:00
2022-04-13 00:00:52 +00:00
2022-03-29 21:03:35 -04:00
2022-04-13 01:07:09 +00:00
2022-04-01 23:28:54 +00:00
2022-04-01 23:28:54 +00:00
2022-04-05 19:35:15 +00:00
2022-03-29 21:03:35 -04:00
2022-04-01 23:28:54 +00:00
2022-04-01 23:28:54 +00:00
2022-04-14 12:27:47 +00:00
2022-04-01 23:28:54 +00:00
2022-04-14 00:55:20 +00:00
2022-03-29 21:03:35 -04:00
2022-04-14 12:27:47 +00:00
2022-03-29 21:03:35 -04:00
2022-03-29 21:03:35 -04:00
2022-04-13 01:07:09 +00:00
2022-03-29 21:03:35 -04:00
2022-04-10 18:38:57 +00:00
2022-04-10 18:38:57 +00:00
2022-04-10 18:38:57 +00:00
2022-04-26 15:45:47 +00:00
2022-04-01 23:28:54 +00:00
2022-04-01 23:28:54 +00:00
2022-03-29 21:03:35 -04:00
2022-04-14 00:55:20 +00:00
2022-03-29 21:03:35 -04:00
2022-04-14 12:27:47 +00:00
2022-04-14 12:27:47 +00:00
2022-04-10 18:38:57 +00:00
2022-04-01 23:28:54 +00:00
2022-04-01 23:28:54 +00:00
2022-04-01 23:28:54 +00:00
2022-04-01 23:28:54 +00:00
2022-04-01 23:28:54 +00:00
2022-04-01 23:28:54 +00:00
2022-04-01 23:28:54 +00:00
2022-03-29 21:03:35 -04:00
2022-04-01 23:28:54 +00:00
2022-04-01 23:28:54 +00:00
2022-03-31 14:31:43 +00:00
2022-03-31 14:31:43 +00:00
2022-04-26 20:59:20 +00:00
2022-04-14 00:55:20 +00:00
2022-04-29 12:38:41 +00:00
2022-04-26 23:41:59 +00:00
2022-03-29 21:03:35 -04:00
2022-04-01 23:28:54 +00:00
2022-04-26 20:59:20 +00:00
2022-03-29 21:03:35 -04:00
2022-03-29 21:03:35 -04:00
2022-04-01 23:28:54 +00:00
2022-04-26 20:59:20 +00:00
2022-04-01 23:28:54 +00:00
2022-03-29 21:03:35 -04:00
2022-04-14 12:27:47 +00:00
2022-05-11 17:42:44 +00:00
2022-04-01 23:28:54 +00:00
2022-04-01 23:28:54 +00:00
2022-04-01 23:28:54 +00:00
2022-04-01 23:28:54 +00:00
2022-04-01 23:28:54 +00:00
2022-04-01 23:28:54 +00:00
2022-04-01 23:28:54 +00:00
2022-04-01 23:28:54 +00:00
2022-03-29 21:03:35 -04:00
2022-04-01 23:28:54 +00:00
2022-04-26 20:59:20 +00:00
2022-04-01 23:28:54 +00:00
2022-04-01 23:28:54 +00:00
2022-03-29 21:03:35 -04:00
2022-03-29 21:03:35 -04:00