Zerologon (CVE-2020-1472): Netlogon RPC Authentication Burst Against DC
Detects a volumetric spike in RPC connection attempts (specifically port 135 followed by Netlogon binding) from a single host to a Domain Controller. This behavior is indicative of the exploit retry mechanism used by Zerologon (CVE-2020-1472) tools, which must attempt the authentication sequence thousands of times due to the low success probability of the all-zero byte ClientCredential.
CQL

