Skip to content

Commit

Permalink
Update windows_powerview_ad_access_control_list_enumeration.yml
Browse files Browse the repository at this point in the history
  • Loading branch information
mvelazc0 committed Apr 24, 2023
1 parent e3139a9 commit 737d03e
Showing 1 changed file with 1 addition and 1 deletion.
Original file line number Diff line number Diff line change
Expand Up @@ -5,7 +5,7 @@ date: '2023-04-20'
author: Mauricio Velazco, Splunk
type: TTP
datamodel: []
description: The following analytic leverages Event ID 4104 to identify the execution of the PowerView powershell commandlets `Get-ObjectAcl` and `Get-DomainObjectAcl`. This commandlets
description: The following analytic leverages Event ID 4104 to identify the execution of the PowerView powershell commandlets `Get-ObjectAcl` or `Get-DomainObjectAcl`. This commandlets
are used to enumerate Access Control List permissions given to Active Directory objects. In an active directory environment, an object is an entity that represents an available resource within
the organizations network, such as domain controllers, users, groups, computers, shares, etc. Maintaining Active Directory permissions is complicated and hard to manage, especially in complex
and large environments with multiple domains. Weak permissions may allow adversaries and red teamers to escalate their privileges in Active Directory. PowerView is a common tool leveraged
Expand Down

0 comments on commit 737d03e

Please sign in to comment.