Skip to content

DC0071 Active Directory Object Access

Item Value
ID DC0071
Version 2.0
Created 20 October 2021
Last Modified 21 October 2025

Log Sources

Name Channel
WinEventLog:Security EventCode=4662
WinEventLog:Security EventCode=4661

Detection Strategy

ID Name Technique Detected
DET0234 Credential Dumping via Sensitive Memory and Registry Access Correlation T1003
DET0007 Detection of Domain Trust Discovery via API, Script, and CLI Enumeration T1482
DET0594 Detection of Unauthorized DCSync Operations via Replication API Abuse T1003.006
DET0055 Detection strategy for Group Policy Discovery on Windows T1615
DET0276 Detection Strategy for Rogue Domain Controller (DCShadow) Registration and Replication Abuse T1207
DET0161 Password Policy Discovery – cross-platform behavior-chain analytics T1201