elastic / elastic/detection-rules

[Meta] Explore Detection Opportunities on Active Directory Object Ownership and Privilege Assignment

Open
#3,522 3 comments 0 reactions 1 assignee Claimed by @w0rk3r View on GitHub
backlog Meta OS: Windows Team: TRADE
Dominant language
Python
Stars
2.7k
Forks
696
Avg merge
4d 17h
Merged PRs (30d)
87

Description

## Parent Epic

https://github.com/elastic/ia-trade-team/issues/276

## Summary

Explore how attackers abuse object ownership issues for privilege escalation, lateral movement, and persistence.

- [ ] Read the whitepaper and decide on scenarios that can be simulated with low to medium effort
- [ ] Document and do it
- [ ] Ship detections and hunting queries
- [ ] STRETCH: Ingest Pipelines to parse basic SDDL

## Resources:

* https://www.hub.trimarcsecurity.com/post/trimarc-whitepaper-owner-or-pwnd
* https://happycamper84.medium.com/get-acl-cheatsheet-f7871edf247f
* https://happycamper84.medium.com/dangerous-rights-cheatsheet-33e002660c1d
* https://happycamper84.medium.com/sddl-what-is-it-does-it-matter-2e5aeaa43b91

### PRs

- TBD

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.