AzureDetection & ResponseRetrospectives

Detecting Netlogon Exploitation: Defender for Cloud and Sentinel KQL

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from September 2020, written in 2026 with the benefit of hindsight.

Attacks on Active Directory — including Zerologon exploitation, DCSync and Kerberos abuse — leave specific traces. Microsoft Defender for Identity and Windows event logs are the main sources.

Signals worth watching

  • Netlogon authentication anomalies against domain controllers (Defender for Identity detects suspected Netlogon privilege elevation attempts).
  • DCSync: replication requests from non-domain-controller machines.
  • Changes to a domain controller's machine account password outside normal schedules.
  • Kerberos anomalies: golden ticket indicators, unusual encryption types, Kerberoasting (many service ticket requests).
  • New members added to Domain Admins, Enterprise Admins or other sensitive groups.

Where the data lives

  • Microsoft Defender for Identity alerts (in the Defender portal).
  • Windows security events from DCs: 4742 (computer account changed), 4662 (directory service access), 4728/4732/4756 (group membership changes), 4769 (Kerberos service ticket).
  • Microsoft Sentinel with the Windows Security Events connector.

A starting query

Additions to privileged AD groups:

SecurityEvent
| where EventID in (4728, 4732, 4756)
| where TargetUserName in~ ("Domain Admins", "Enterprise Admins", "Administrators", "Schema Admins")
| project TimeGenerated, Computer, SubjectUserName, MemberName, TargetUserName

Response

  1. Treat any confirmed DC compromise as a full domain compromise.
  2. Isolate affected systems and engage incident response specialists.
  3. Reset the KRBTGT account password twice (with appropriate spacing) if golden ticket use is suspected.
  4. Check Entra Connect and synchronized privileged accounts for cloud-side impact.
detect netlogon exploitationZerologon2020

More on this story