Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

How to Defend Against Active Directory Attacks That Leave No Trace

Summary

Why some AD attacks leave no trace: DCShadow injects changes through the replication stream, malicious GPO edits like Ryuk's lack log detail, and ZeroLogon used crafted Netlogon messages—so SIEM-only monitoring misses them.
Published
Collected

original ↗