{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/active-directory-integrated-dns/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Active Directory","Active Directory Integrated DNS"],"_cs_severities":["low"],"_cs_tags":["credential-access","windows","active-directory"],"_cs_type":"advisory","_cs_vendors":["Microsoft"],"content_html":"\u003cp\u003eActive Directory Integrated DNS (ADIDNS) is a core component of AD DS, storing DNS zones as AD objects. The default permission settings allow any authenticated user to create DNS-named records. This creates an opportunity for attackers to perform Dynamic Spoofing attacks by monitoring LLMNR/NBT-NS requests and creating DNS-named records to target systems or specific services like WPAD. This attack can enable credential access by redirecting traffic through attacker-controlled systems, leading to the capture of sensitive information. This activity is detectable by monitoring Windows event code 5137 related to DNS record creation and filtering out legitimate system accounts.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eThe attacker gains initial access to a domain-joined system, possibly through compromised credentials or phishing.\u003c/li\u003e\n\u003cli\u003eThe attacker passively monitors LLMNR/NBT-NS broadcast traffic to identify systems being requested on the network.\u003c/li\u003e\n\u003cli\u003eUpon observing a request for a target system (e.g., WPAD), the attacker creates a DNS-named record in ADIDNS that resolves the target system's name to an attacker-controlled IP address. This leverages the default permissions in ADIDNS that allow authenticated users to create DNS records.\u003c/li\u003e\n\u003cli\u003eWhen a legitimate user attempts to access the target system, the DNS query resolves to the attacker's IP address.\u003c/li\u003e\n\u003cli\u003eThe user's traffic is redirected to the attacker's system.\u003c/li\u003e\n\u003cli\u003eThe attacker intercepts the user's credentials or other sensitive information.\u003c/li\u003e\n\u003cli\u003eThe attacker may relay captured credentials to other systems on the network.\u003c/li\u003e\n\u003cli\u003eThe attacker achieves credential access and lateral movement within the network.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows attackers to intercept network traffic, steal credentials, and potentially gain unauthorized access to sensitive systems and data within the Active Directory domain. While the severity is low, it can be a stepping stone to further, more damaging attacks.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eEnable \u0026quot;Audit Directory Service Changes\u0026quot; to generate the necessary Windows Security Event Logs (event code 5137) for detection.\u003c/li\u003e\n\u003cli\u003eDeploy the Sigma rule \u003ccode\u003eCreation of a DNS-Named Record\u003c/code\u003e to detect suspicious DNS record creation events.\u003c/li\u003e\n\u003cli\u003eImplement stricter access controls on DNS record creation within Active Directory to limit permissions to only necessary and trusted accounts.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2024-05-22T12:00:00Z","date_published":"2024-05-22T12:00:00Z","id":"https://feed.craftedsignal.io/briefs/2024-05-adidns-record-creation/","summary":"Detection of DNS record creation by non-system accounts within Active Directory Integrated DNS (ADIDNS), which attackers can abuse to perform Dynamic Spoofing attacks, potentially targeting services like WPAD for credential access.","title":"Suspicious DNS-Named Record Creation in Active Directory Integrated DNS","url":"https://feed.craftedsignal.io/briefs/2024-05-adidns-record-creation/"}],"language":"en","title":"CraftedSignal Threat Feed - Active Directory Integrated DNS","version":"https://jsonfeed.org/version/1.1"}