CTD-000126

AD domain with restored domain controllers

Medium
Active Directory
Defense Evasion
v26

Signature Identity

CTD-000126
Threat ID
26
Version
IOE
Indicator Type

Threat Description

A threat actor might use authoritative restore to modify password and get access to a specific user account. Most changes can be recovered with the rollback in Cayosoft Guardian, so any instance of using an authoritative restore might be an indication of threat activities.

MITRE ATT&CK: Attack Tactics

Defense Evasion

D3FEND: Defend Tactics

Restore User Account Access

Remediation

Review the changes associated with the authoritative restore using Change History in Cayosoft Guardian.
Consider changing the passwords of the affected accounts.

Frequently Asked Questions

What does AD domain with restored domain controllers mean?

AD domain with restored domain controllers means that one or more domain controllers in the Active Directory environment have been restored from backup, potentially bringing back changes made by an attacker.

A restored domain controller does not immediately grant administrative control, but it can allow an attacker to modify user account access and evade detection through unauthorized password resets or group membership modifications. This is because the restored domain controller may still contain malicious changes made by the attacker.

Attackers can use the opportunity of a restored domain controller to modify user account access, allowing them to reset passwords or modify group memberships and maintain unauthorized access. This can also enable attackers to evade detection by making changes that are not immediately apparent.

Cayosoft Guardian detects AD domain with restored domain controllers by continuously monitoring changes made to the Active Directory environment and flagging potential security issues for administrator review, providing visibility into unauthorized access.

Cayosoft Guardian helps reduce the risk of AD domain with restored domain controllers by providing real-time monitoring and alerting administrators to potential security issues, including unauthorized changes to user account access. This enables administrators to take action to remediate, such as reviewing change history and ensuring proper documentation and approval.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Active Directory
Themes
Account protection
Attack Tactics
Defense Evasion
Defend Tactics
Restore User Account Access
Indicator Types
IOE
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical