Is there an option FortiNDR be configured with the IP address of the AD server to detect AD attacks?
Hey Everyone,
Is there an option FortiNDR be configured with the IP address of the AD server to detect AD attacks?
I did see Device Enrichment | FortiNDR 7.6.2 | Fortinet Document Library but I was wondering not about enriching the other hosts but for FortiNDR to monitor the AD server IP address or FortiNDR to autodiscover it, so to detect Pass-the-Hash / Pass-the-Ticket, Kerberoasting, DC Shadow, DCSync or Golden/Silver Ticket attacks Active Directory Attacks ?
For example by FortiNDR knowing that there are two AD servers on ip addresses 1.1.1.1 and 1.1.1.2 then if another host sends DCSync requests using MS-DRSR protocol to 1.1.1.1 or 1.1.1.2 this will suggest AD attack as only AD servers should use DCSync between them.
