{"id":"T1207","name":"Rogue Domain Controller","url":"https://attack.mitre.org/techniques/T1207","tactics":["defense-impairment"],"platforms":["Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0276","stix_id":"x-mitre-detection-strategy--f012e122-9f78-4370-a481-d2efaa181359","name":"Detection Strategy for Rogue Domain Controller (DCShadow) Registration and Replication Abuse","url":"https://attack.mitre.org/detectionstrategies/DET0276","analytics":[{"id":"AN0770","stix_id":"x-mitre-analytic--34fecfa5-24fb-46c1-955f-68ecd4cc402c","name":"Analytic 0770","description":"Detection of rogue Domain Controller registration and Active Directory replication abuse by correlating: (1) creation/modification of nTDSDSA and server objects in the Configuration partition, (2) unexpected usage of Directory Replication Service SPNs (GC/ or E3514235-4B06-11D1-AB04-00C04FC2DCD2), (3) replication RPC calls (DrsAddEntry, DrsReplicaAdd, GetNCChanges) originating from non-DC hosts, and (4) Kerberos authentication by non-DC machines using DRS-related SPNs. These events in combination, especially from hosts outside the Domain Controllers OU, may indicate DCShadow or rogue DC activity.","url":"https://attack.mitre.org/detectionstrategies/DET0276#AN0770","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=4928","data_component":"DC0087","data_component_name":"Active Directory Object Creation","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Security","channel":"EventCode=4929","data_component":"DC0084","data_component_name":"Active Directory Credential Request","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Security","channel":"EventCode=4662","data_component":"DC0071","data_component_name":"Active Directory Object Access","log_source_slug":"wineventlog-security"},{"name":"m365:dirsync","channel":"Replication cookie changes involving Configuration partition with new server/nTDSDSA objects.","data_component":"DC0066","data_component_name":"Active Directory Object Modification","log_source_slug":"m365-dirsync"},{"name":"NSM:Flow","channel":"DrsAddEntry, DrsReplicaAdd, GetNCChanges calls between non-DC and DCs.","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"TimeWindow","description":"Window (seconds) between nTDSDSA object creation and subsequent replication traffic from same host (default 300s)."},{"field":"AllowedReplicationPartners","description":"List of legitimate DCs authorized for replication to reduce false positives."},{"field":"SuspiciousSPNs","description":"SPNs indicating replication service usage (GC/, GUID E3514235-4B06-11D1-AB04-00C04FC2DCD2)."},{"field":"NonDCObjectCreationAlert","description":"Trigger alerts only when AD object creation is by accounts not in Domain Admins or Enterprise Admins groups."}],"live":true,"detection_strategies":["DET0276"],"techniques":["T1207"]}],"live":true,"version":"1.0","techniques":["T1207"]}],"sigma_rules":[{"id":"20d96d95-5a20-4cf1-a483-f3bda8a7c037","title":"Add or Remove Computer from DC","author":"frack113","status":"test","level":"low","date":"2022-10-14","modified":null,"description":"Detects the creation or removal of a computer. Can be used to detect attacks such as DCShadow via the creation of a new SPN.","references":["https://github.com/Yamato-Security/EnableWindowsLogSettings/blob/7f6d755d45ac7cc9fc35b0cbf498e6aa4ef19def/ConfiguringSecurityLogAuditPolicies.md","https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-10/security/threat-protection/auditing/event-4741","https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-10/security/threat-protection/auditing/event-4743"],"logsource":{"product":"windows","service":"security"},"tags":["attack.defense-impairment","attack.t1207"],"path":"rules/windows/builtin/security/win_security_add_remove_computer.yml","techniques":["T1207"],"cves":[]},{"id":"32e19d25-4aed-4860-a55a-be99cb0bf7ed","title":"Possible DC Shadow Attack","author":"Ilyas Ochkov, oscd.community, Chakib Gzenayi (@Chak092), Hosni Mribah","status":"test","level":"medium","date":"2019-10-25","modified":"2022-10-17","description":"Detects DCShadow via create new SPN","references":["https://twitter.com/gentilkiwi/status/1003236624925413376","https://gist.github.com/gentilkiwi/dcc132457408cf11ad2061340dcb53c2","https://web.archive.org/web/20180203014709/https://blog.alsid.eu/dcshadow-explained-4510f52fc19d?gi=c426ac876c48"],"logsource":{"product":"windows","service":"security"},"tags":["attack.credential-access","attack.defense-impairment","attack.t1207"],"path":"rules/windows/builtin/security/win_security_possible_dc_shadow.yml","techniques":["T1207"],"cves":[]}],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}