DCShadow - Rogue Domain Controller Registration Detected
This rule detects the configuration of 'Trusted for Delegation' on a computer or user account, followed by a modification to the Active Directory nTDSDSA object on the same host. This combination is a classic indicator of setting up an account for Kerberos delegation attacks, often related to the creation of rogue domain controllers or setting up pivot points for lateral movement.
Microsoft Sentinel (KQL)

