Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0210 — Abuse of Domain Accounts
DET0210

Abuse of Domain Accounts

4 analytic(s) · 1 technique(s) detected

Analytics

4
AN0590 Analytic 0590
Windows

Detection of suspicious logon behavior using valid domain accounts across multiple hosts, off-hours, or simultaneous sessions from geographically distant locations.

WinEventLog:Security EventCode=4624, 4625, 4768, 4769 WinEventLog:Sysmon EventCode=1 WinEventLog:Sysmon EventCode=3, 22
[TimeWindow] Tune for detection of off-hours or abnormal logon spikes.
[UserContext] Scope to sensitive domain accounts (e.g., Domain Admins).
[LogonType] Distinguish between interactive, service, and network logons.
AN0591 Analytic 0591
Linux

Use of domain accounts via sssd or winbind for logon activity outside of typical patterns, especially on sensitive systems or with lateral movement tools.

auditd:SYSCALL pam_authenticate, sshd linux:syslog sssd / sudo logs
[HostnameScope] Filter to high-value systems (e.g., domain-joined servers).
[AccountDomain] Identify trusted domains versus external or misconfigured domains.
AN0592 Analytic 0592
macOS

Domain logins using network accounts or mobile accounts via Open Directory or Active Directory plugins, especially outside business hours or on atypical endpoints.

macos:unifiedlog log show --predicate 'eventMessage contains "Authentication"'
[UserLocation] Geo-IP or VPN source context for abnormal remote access.
[LogonMethod] Control for expected services (e.g., GUI login vs. SSH).
AN0593 Analytic 0593
ESXi

Login to vSphere or ESXi hosts using domain accounts, especially those associated with vpxuser or unexpected group memberships.

esxi:vpxd /var/log/vmware/vpxd.log esxi:hostd /var/log/hostd.log
[AccountType] Prioritize detection on accounts with elevated access.
[LoginInterface] Distinguish interactive UI login from API or SSH access.

Detected Techniques

1

Details

MITRE ID
DET0210
STIX ID
x-mitre-detection-strategy--ba7a75c6-fcf5-4f36-8908-1fe1c30f690f
Analytics
4
Techniques Detected
1
By Tactic
Stealth
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.