Domain Accounts
Where this stands
A reviewer read the telemetry and concluded there is nothing here to detect that a sibling technique does not already cover.
Every analytic in DET0210 describes a baseline comparison, not an event. AN0590 asks for 'logon behavior across multiple hosts, off-hours, or simultaneous sessions from geographically distant locations' over Security 4624/4625/4768/4769; AN0591 asks for sssd/winbind logons 'outside of typical patterns'; AN0592 asks for Open Directory logins 'outside business hours or on atypical endpoints'. All three need counting, time-of-day windows, or per-account history, and lib/sigma models none of those — no aggregations, no timeframes, no near. Stripped of the baseline, the residue is 'a domain account authenticated', which every 4624 in a domain satisfies: the rule would fire on every successful logon in the estate, which is the silent failure this corpus exists to avoid. […]
What the technique is
Adversaries may obtain and abuse credentials of a domain account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Domain accounts are those managed by Active Directory Domain Services where access and permissions are configured across systems and services that are part of that domain. Domain accounts can cover users, administrators, and services. Adversaries may compromise domain accounts, some with a high level of privileges, through various means such as OS Credential Dumping or password reuse, allowing access to privileged resources of the domain.
Read it on attack.mitre.orgWhat MITRE says you would watch
- AN0590
Detection of suspicious logon behavior using valid domain accounts across multiple hosts, off-hours, or simultaneous sessions from geographically distant locations.
- AN0591
Use of domain accounts via sssd or winbind for logon activity outside of typical patterns, especially on sensitive systems or with lateral movement tools.
- AN0592
Domain logins using network accounts or mobile accounts via Open Directory or Active Directory plugins, especially outside business hours or on atypical endpoints.
Technique names and descriptions © MITRE ATT&CK®, CC BY 4.0. Not endorsed by MITRE.