DCShadow - Rogue Domain Controller Registration Detected

This rule detects the configuration of 'Trusted for Delegation' on a computer or user account, followed by a modification to the Active Directory nTDSDSA object on the same host. This combination is a classic indicator of setting up an account for Kerberos delegation attacks, often related to the creation of rogue domain controllers or setting up pivot points for lateral movement.