Why Most Organizations Still Can’t Defend against DCShadow
semperis.com | blog | #active-directory | #backdoor | #mimikatz | #persistence | #dcshadow | #event-logging
Summary
How DCShadow works: any Windows server can impersonate a domain controller and inject changes into AD's replication stream—bypassing security event logs, with no patch to close the technique.
- Published
- Collected
Skip to content