• CommunityEnterprisePlans
  • Intel Exchange
    Intel ExchangeDetections
  • Resources
  • About
  • Leaderboard
Join CommunitySign In
    All Detections

    Zerologon (CVE-2020-1472) DC Machine Account Reset / Netlogon Anomaly

    avatar
    GlassDiceBearhttps://www.dicebear.comhttps://creativecommons.org/publicdomain/zero/1.0/„Glass” (https://www.dicebear.com) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)
    Ibrahim Saud@tektrix
    •updated 8 days ago•0•0•2

    Detects potential exploitation attempts of the Zerologon vulnerability (CVE-2020-1472) by monitoring for Domain Controller machine account password resets (Event 4742) targeting DC computer accounts, and insecure Netlogon RPC channel events (Event 5829) triggered when vulnerable clients or tools attempt connections.

    Splunk (SPL)

    Tags

    T1210 - Exploitation of Remote ServicesAuthentication AttemptExploit AttemptWindowsWindows Eventlog SecurityActive Directory Domain ServicesCVE-2020-1472spl

    Found in

    • Rhysida Extortion Breach of Berlin Senate AdministrationsLast updated 16 days ago
    • Operation Escaneo Campaign Against LATAM Critical InfrastructureLast updated Jun 18, 2026
    • Critical RCE Vulnerability in Windows Netlogon Service (CVE-2026-41089)Last updated Jun 17, 2026

    Community Inspired.
    AI Enhanced.
    Better Detections.

    Follow Us

    Company

    • About
    • Leaderboard

    Product

    • Community
    • Enterprise
    • Plans

    © 2026 Copyright. All Rights Reserved.

    Privacy PolicyTerms of Service

    Sign up to view this detection

    or

    Already have an account?