As cited
Copy frozen at (site build).
threat intel
From Code to Coverage (Part 6): What netlogon.log Sees That Event 1644 Never Will
A researcher demonstrates that the ldapnomnom tool bypasses Windows audit Event 1644 by using LDAP Ping operations, which leaves no traces in standard event logs. The article explains where defenders can detect these activities in netlogon.log when standard LDAP audit events fail to capture the behavior.
Why it matters: Defenders relying solely on Event 1644 for LDAP attack detection will miss ldapnomnom exploitation; understanding netlogon.log coverage is critical for detecting this active evasion technique.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
From Code to Coverage (Part 6): What netlogon.log Sees That Event 1644 Never Will
A researcher demonstrates that the ldapnomnom tool bypasses Windows audit Event 1644 by using LDAP Ping operations, which leaves no traces in standard event logs. The article explains where defenders can detect these activities in netlogon.log when standard LDAP audit events fail to capture the behavior.
Why it matters: Defenders relying solely on Event 1644 for LDAP attack detection will miss ldapnomnom exploitation; understanding netlogon.log coverage is critical for detecting this active evasion technique.
- Source published
- First seen by Cybersecurity Tracker