2018 IEEE Conference on Application, Information and Network Security (AINS) 2018
DOI: 10.1109/ains.2018.8631459
|View full text |Cite
|
Sign up to set email alerts
|

Detecting Abuse of Domain Administrator Privilege Using Windows Event Log

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
1
1
1

Citation Types

0
2
0

Year Published

2020
2020
2024
2024

Publication Types

Select...
3
2
1

Relationship

0
6

Authors

Journals

citations
Cited by 7 publications
(3 citation statements)
references
References 0 publications
0
2
0
Order By: Relevance
“…The title should be a comma-separated list with technical considerations. 33 The server includes additional extensions and is not required if their conditions are met (e.g., if extension A requires a specific GoLang that is not available on the server, then extension A is almost certainly not included at this point). It is possible to set default values for these alternatives when Sandcat is pulled from an attacker's machine.…”
Section: Methodsmentioning
confidence: 99%
“…The title should be a comma-separated list with technical considerations. 33 The server includes additional extensions and is not required if their conditions are met (e.g., if extension A requires a specific GoLang that is not available on the server, then extension A is almost certainly not included at this point). It is possible to set default values for these alternatives when Sandcat is pulled from an attacker's machine.…”
Section: Methodsmentioning
confidence: 99%
“…Fujimoto et al compared methods for detecting the abuse of domain administrator credentials proposed by other researchers. Since many detection methods are interested in detecting specific CVE's and attack methodologies like "Mimi Katz" or "Kerberoasting," the researchers are interested in combining the eclectic methodologies into a central repository of detection methods that can be used to detect abuse of domain administrator credentials into a single tool [29]. The researchers outline useful methods proposed by other researchers to detect abuse of domain administrator credentials.…”
Section: Detecting Abuse Of Domain Administrator Privilege Using Wind...mentioning
confidence: 99%
“…The authors in [52] proposed a technique to detect attacks involving domain administrator accounts using Windows event logs. They proved that their scheme is efficient in detecting such attacks.…”
Section: Active Directory Attack Detectionmentioning
confidence: 99%