As cited
Copy frozen at (site build).
threat intel
SDFlags | Huntress
A security investigator discovered that SDFlags, an overlooked field in Event 1644 logs, can reveal attack paths through analysis of nTSecurityDescriptor attributes in Active Directory. This finding enables creation of high-confidence detection signatures for identifying suspicious security descriptor modifications. The discovery highlights how neglected log fields can provide valuable forensic indicators.
Why it matters: Blue teams and Active Directory defenders need to monitor SDFlags changes to detect lateral movement and privilege escalation attempts that exploit security descriptor modifications.
- Source published
- First seen by Cybersecurity Tracker