CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

From Code to Coverage (Part 6): What netlogon.log Sees That Event 1644 Never Will

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 666

As cited

Copy frozen at (site build).

threat intel

From Code to Coverage (Part 6): What netlogon.log Sees That Event 1644 Never Will

A researcher demonstrates that the ldapnomnom tool bypasses Windows audit Event 1644 by using LDAP Ping operations, which leaves no traces in standard event logs. The article explains where defenders can detect these activities in netlogon.log when standard LDAP audit events fail to capture the behavior.

Why it matters: Defenders relying solely on Event 1644 for LDAP attack detection will miss ldapnomnom exploitation; understanding netlogon.log coverage is critical for detecting this active evasion technique.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

From Code to Coverage (Part 6): What netlogon.log Sees That Event 1644 Never Will

A researcher demonstrates that the ldapnomnom tool bypasses Windows audit Event 1644 by using LDAP Ping operations, which leaves no traces in standard event logs. The article explains where defenders can detect these activities in netlogon.log when standard LDAP audit events fail to capture the behavior.

Why it matters: Defenders relying solely on Event 1644 for LDAP attack detection will miss ldapnomnom exploitation; understanding netlogon.log coverage is critical for detecting this active evasion technique.

VendorsMicrosoft
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary