elastic / elastic/detection-rules

[Meta] Linux Active Directory Tooling detection

Open
#3,523 1 comment 1 reaction 1 assignee Claimed by @w0rk3r View on GitHub
backlog Meta OS: Linux Team: TRADE
Dominant language
Python
Stars
2.7k
Forks
696
Avg merge
4d 17h
Merged PRs (30d)
87

Description

## Summary

Explore detection opportunities for Linux tooling used to hack into active directory environments.

```[tasklist]
### Tasks
- [ ] TBD
```

## Goals

- TBD

## Resources:

https://github.com/ly4k/Certipy
https://github.com/Pennyw0rth/NetExec
https://github.com/fortra/impacket
https://www.onsecurity.io/blog/abusing-kerberos-from-linux/
https://enox.zip/Active+Directory/Impacket+Unleashed+Series/0x01+Impacket+Unleashed+-+Introduction

### PRs

* TBD

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.