DCShadow Rogue DC Registration via nTDSDSA or SPN (T1207)

This rule detects indicators of the DCShadow attack technique by monitoring for the creation of nTDSDSA objects (which define domain controllers) or the addition of suspicious Service Principal Names (SPNs) often used in DCShadow simulations (GC/ or E3514235-4B06) to computer accounts. These indicators suggest an attacker is attempting to register a rogue Domain Controller to manipulate Active Directory data.