From 57ca66d09d2d78fb7088fc517cc59b212fccfb09 Mon Sep 17 00:00:00 2001 From: Ming Di Leom <2809763-curben@users.noreply.gitlab.com> Date: Mon, 9 Jun 2025 06:52:25 +0000 Subject: [PATCH] page(threat-hunting): domain admins report --- source/threat-hunting/index.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/source/threat-hunting/index.md b/source/threat-hunting/index.md index c06c560..562b197 100644 --- a/source/threat-hunting/index.md +++ b/source/threat-hunting/index.md @@ -50,7 +50,7 @@ SPL: | collect index="ldapsearch" ``` -## Monthly Domain Admins Report +## Domain Admins Report References: [1](https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/plan/security-best-practices/appendix-b--privileged-accounts-and-groups-in-active-directory#built-in-privileged-accounts-and-groups), [2](http://www.selfadsi.org/ldap-filter.htm#BitAndOr), [3](https://learn.microsoft.com/en-us/troubleshoot/windows-server/identity/useraccountcontrol-manipulate-account-properties#list-of-property-flags), [4](https://learn.microsoft.com/en-us/windows/win32/adsi/search-filter-syntax#operators) SPL: