Detecting Netlogon Exploitation: Defender for Cloud and Sentinel KQL
Retrospective: this article looks back at events from September 2020, written in 2026 with the benefit of hindsight.
Attacks on Active Directory — including Zerologon exploitation, DCSync and Kerberos abuse — leave specific traces. Microsoft Defender for Identity and Windows event logs are the main sources.
Signals worth watching
- Netlogon authentication anomalies against domain controllers (Defender for Identity detects suspected Netlogon privilege elevation attempts).
- DCSync: replication requests from non-domain-controller machines.
- Changes to a domain controller's machine account password outside normal schedules.
- Kerberos anomalies: golden ticket indicators, unusual encryption types, Kerberoasting (many service ticket requests).
- New members added to Domain Admins, Enterprise Admins or other sensitive groups.
Where the data lives
- Microsoft Defender for Identity alerts (in the Defender portal).
- Windows security events from DCs: 4742 (computer account changed), 4662 (directory service access), 4728/4732/4756 (group membership changes), 4769 (Kerberos service ticket).
- Microsoft Sentinel with the Windows Security Events connector.
A starting query
Additions to privileged AD groups:
SecurityEvent
| where EventID in (4728, 4732, 4756)
| where TargetUserName in~ ("Domain Admins", "Enterprise Admins", "Administrators", "Schema Admins")
| project TimeGenerated, Computer, SubjectUserName, MemberName, TargetUserName
Response
- Treat any confirmed DC compromise as a full domain compromise.
- Isolate affected systems and engage incident response specialists.
- Reset the KRBTGT account password twice (with appropriate spacing) if golden ticket use is suspected.
- Check Entra Connect and synchronized privileged accounts for cloud-side impact.
- Zerologon (Aug–Sept 2020): Taking Over a Domain Controller in Seconds Incident Teardowns
- How to Patch and Monitor Domain Controllers in Hybrid Azure Environments How-To & Hardening
- CIO Brief: Hybrid Identity Means On-Prem Flaws Become Cloud Flaws CIO Briefings