Suspected overpass-the-hash attack (Kerberos) |
2002 |
Medium |
Lateral movement |
Account enumeration reconnaissance |
2003 |
Medium |
Discovery |
Suspected Brute Force attack (LDAP) |
2004 |
Medium |
Credential access |
Suspected DCSync attack (replication of directory services) |
2006 |
High |
Credential access, Persistence |
Network mapping reconnaissance (DNS) |
2007 |
Medium |
Discovery |
Suspected Golden Ticket usage (encryption downgrade) |
2009 |
Medium |
Persistence, Privilege Escalation, Lateral movement |
Suspected Skeleton Key attack (encryption downgrade) |
2010 |
Medium |
Persistence, Lateral movement |
User and IP address reconnaissance (SMB) |
2012 |
Medium |
Discovery |
Suspected Golden Ticket usage (forged authorization data) |
2013 |
High |
Credential access |
Honeytoken activity |
2014 |
Medium |
Credential access, Discovery |
Suspected identity theft (pass-the-hash) |
2017 |
High |
Lateral movement |
Suspected identity theft (pass-the-ticket) |
2018 |
High or Medium |
Lateral movement |
Remote code execution attempt |
2019 |
Medium |
Execution, Persistence, Privilege escalation, Defense evasion, Lateral movement |
Malicious request of Data Protection API master key |
2020 |
High |
Credential access |
User and Group membership reconnaissance (SAMR) |
2021 |
Medium |
Discovery |
Suspected Golden Ticket usage (time anomaly) |
2022 |
High |
Persistence, Privilege Escalation, Lateral movement |
Suspected Brute Force attack (Kerberos, NTLM) |
2023 |
Medium |
Credential access |
Suspicious additions to sensitive groups |
2024 |
Medium |
Persistence, Credential access, |
Suspicious VPN connection |
2025 |
Medium |
Defense evasion, Persistence |
Suspicious service creation |
2026 |
Medium |
Execution, Persistence, Privilege Escalation, Defense evasion, Lateral movement |
Suspected Golden Ticket usage (nonexistent account) |
2027 |
High |
Persistence, Privilege Escalation, Lateral movement |
Suspected DCShadow attack (domain controller promotion) |
2028 |
High |
Defense evasion |
Suspected DCShadow attack (domain controller replication request) |
2029 |
High |
Defense evasion |
Data exfiltration over SMB |
2030 |
High |
Exfiltration, Lateral movement, Command and control |
Suspicious communication over DNS |
2031 |
Medium |
Exfiltration |
Suspected Golden Ticket usage (ticket anomaly) |
2032 |
High |
Persistence, Privilege Escalation, Lateral movement |
Suspected Brute Force attack (SMB) |
2033 |
Medium |
Lateral movement |
Suspected use of Metasploit hacking framework |
2034 |
Medium |
Lateral movement |
Suspected WannaCry ransomware attack |
2035 |
Medium |
Lateral movement |
Remote code execution over DNS |
2036 |
Medium |
Lateral movement, Privilege escalation |
Suspected NTLM relay attack |
2037 |
Medium or Low if observed using signed NTLM v2 protocol |
Lateral movement, Privilege escalation |
Security principal reconnaissance (LDAP) |
2038 |
Medium |
Credential access |
Suspected NTLM authentication tampering |
2039 |
Medium |
Lateral movement, Privilege escalation |
Suspected Golden Ticket usage (ticket anomaly using RBCD) |
2040 |
High |
Persistence |
Suspected rogue Kerberos certificate usage |
2047 |
High |
Lateral movement |
Active Directory attributes reconnaissance (LDAP) |
2210 |
Medium |
Discovery |
Suspected SMB packet manipulation (CVE-2020-0796 exploitation) - (preview) |
2406 |
High |
Lateral movement |
Suspected Kerberos SPN exposure (external ID 2410) |
2410 |
High |
Credential access |
Suspected Netlogon privilege elevation attempt (CVE-2020-1472 exploitation) |
2411 |
High |
Privilege Escalation |
Suspected AS-REP Roasting attack |
2412 |
High |
Credential access |
Exchange Server Remote Code Execution (CVE-2021-26855) |
2414 |
High |
Lateral movement |
Suspected exploitation attempt on Windows Print Spooler service |
2415 |
High or Medium |
Lateral movement |
Suspicious network connection over Encrypting File System Remote Protocol |
2416 |
High or Medium |
Lateral movement |
Suspicious modification of a sAMNameAccount attribute (CVE-2021-42278 and CVE-2021-42287 exploitation) |
2419 |
High |
Credential access |