GitHub - shellster/DCSYNCMonitor: Monitors for DCSYNC and DCSHADOW attacks and create custom Windows Events for these events.
Tags
attack-pattern: | Data Dcsync - T1003.006 Ip Addresses - T1590.005 Server - T1583.004 Server - T1584.004 Windows Service - T1543.003 Tool - T1588.002 Dcshadow - T1207 |
Common Information
Type | Value |
---|---|
UUID | e5a6fff6-67a1-49e5-959f-5077ff4a0c9c |
Fingerprint | 158ee143e9ebf1c7 |
Analysis status | DONE |
Considered CTI value | 0 |
Text language | |
Published | Jan. 1, 2022, midnight |
Added to db | Sept. 26, 2022, 9:31 a.m. |
Last updated | Nov. 17, 2024, 11:40 p.m. |
Headline | shellster/DCSYNCMonitor |
Title | GitHub - shellster/DCSYNCMonitor: Monitors for DCSYNC and DCSHADOW attacks and create custom Windows Events for these events. |
Detected Hints/Tags/Attributes | 26/1/23 |
Source URLs
Redirection | Url | |
---|---|---|
Details | Source | https://github.com/shellster/DCSYNCMonitor |
URL Provider
Attributes
Details | Type | #Events | CTI | Value |
---|---|---|---|---|
Details | Domain | 768 | www.youtube.com |
|
Details | Domain | 4128 | github.com |
|
Details | Domain | 258 | nmap.org |
|
Details | Domain | 1 | tcppacket.data |
|
Details | Domain | 5 | www.tcpdump.org |
|
Details | Domain | 2 | code.msdn.microsoft.com |
|
Details | Domain | 62 | stackoverflow.com |
|
Details | Domain | 12 | keybase.io |
|
Details | File | 1 | dcsyncmonitorservice.exe |
|
Details | File | 6 | wpcap.dll |
|
Details | File | 7 | packet.dll |
|
Details | File | 1 | dcsyncmonitor.exe |
|
Details | File | 1 | dcmonitorservice.exe |
|
Details | File | 1 | monitor.cpp |
|
Details | File | 1 | tcppacket.dat |
|
Details | Github username | 3 | shellster |
|
Details | Url | 1 | https://www.youtube.com/watch?v=olnd9qzfajc |
|
Details | Url | 1 | https://github.com/shellster/dcsyncmonitor/raw/master/release/dcsyncmonitorservice.exe |
|
Details | Url | 1 | https://github.com/shellster/dcsyncmonitor/raw/master/x64/release/dcsyncmonitorservice.exe |
|
Details | Url | 1 | https://nmap.org/npcap |
|
Details | Url | 1 | https://www.tcpdump.org/sniffex.c |
|
Details | Url | 1 | https://code.msdn.microsoft.com/windowsapps/cppwindowsservice-cacf4948 |
|
Details | Url | 1 | https://stackoverflow.com/questions/8559222/write-an-event-to-the-event-viewer |