Skip to main content
Prasanna1
Staff
Staff
August 12, 2020

HUNTS- DCShadow (T1207)

  • August 12, 2020
  • 0 replies
  • 136 views

HUNTS- DCShadow (T1207)

Version 1.0


ATT&CK Technique: DCShadow (T1207)


What this playbook hunts for:

  • DCShadow is a Mimikatz module that makes a regular Windows host attempt to masquerade as an Active Directory Domain Controller and make real changes to a network’s live Active Directory environment. This playbook hunts for execution of the DCShadow module of Mimikatz via the command line and for abnormal network traffic that may be indicative of that execution.

How the playbook works:

  • Generates SIEM query for Sysmon Event ID 1 logs where the command line argument passed contains “lsadump::dcshadow”

  • Queries the IDS for network alerts for observed network traffic indicative of a non-Domain Controller pushing changes to Active Directory using the DRSUAPI.


What results are expected:

  • Process Name, process ID, MD5 hash, execution time, hostname, and username for a detection of Mimikatz calling the DCShadow module

  • Source and destination IP addresses, ports, hostnames, and execution time for a detection of abnormal network traffic


Common follow-on actions:

  • Detect lateral movement (identify other potentially compromised hosts)

  • Quarantine host


What inputs are necessary:

  • SIEM

  • Logs: Sysmon Event ID 1: Process creation

  • Hunt start time

  • IDS


What subroutine playbooks are needed:

  • Create and Link Alerts from Hunt (Host-based)

  • Link Asset to Network Alert

  • Link Asset to Alert (POST-CREATE)

  • Create User from Alert (Host)

  • Create Indicators from MITRE Alert (Process and Hash)

  • Deduplicate Comments (Hunt)


What configurations are needed:

  • Sysmon logging enabled to include logging Event ID 1

  • IDS alerting to include a signature that detects when IP addresses that are not associated with Domain Controllers are pushing Active Directory changes to IP addresses that are known Domain Controllers. There are publicly available Snort signatures for this activity, or you can write your own.


False Positive Potential: Low

  • The host-based detection portion of this playbook is unlikely to generate false positives because it is searching for specific and unique command line arguments.

  • The network-based detection portion of this playbook should not generate many false positives either, assuming you filter out legitimate Domain-Controller-to-Domain-Controller network traffic.

    • To be clear, the network traffic that DCShadow generates looks exactly like the network traffic that real Domain Controllers send to each other all the time. The signatures should be designed to detect non-Domain Controller assets on the network generating traffic that should only be coming from true Domain Controllers.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!