How to Defend Against Active Directory Attacks That Leave No Trace
semperis.com | blog | #siem | #active-directory | #detection | #group-policy | #zerologon | #dcshadow
Summary
Why some AD attacks leave no trace: DCShadow injects changes through the replication stream, malicious GPO edits like Ryuk's lack log detail, and ZeroLogon used crafted Netlogon messages—so SIEM-only monitoring misses them.
- Published
- Collected
Skip to content