DCShadow Attack

DCShadow registers a rogue Domain Controller in Active Directory, triggers a replication event from it to a real DC, and uses that replication to push arbitrary AD object changes — bypassing the domain controller's audit logging entirely. No Event 4662, no Event 5136. The changes arrive via the replication protocol, which most SIEM systems don't monitor.

Related Articles