Rule Content
- title: Password Change on Directory Service Restore Mode (DSRM) Account
id: 53ad8e36-f573-46bf-97e4-15ba5bf4bb51
status: stable
description: The Directory Service Restore Mode (DSRM) account is a local administrator
account on Domain Controllers. Attackers may change the password to gain persistence.
references:
- https://adsecurity.org/?p=1714
author: Thomas Patzke
tags:
- attack.persistence
- attack.privilege_escalation
- attack.t1098
logsource:
product: windows
service: security
category: null
detection:
selection:
EventID: 4794
condition: selection
falsepositives:
- Initial installation of a domain controller
level: high