Language:
A rogue domain controller has been detected in the monitored infrastructure. It could allow attackers to steal credentials.
Illegitimate domain controllers can lead to credentials theft and should be removed.
Active Directory: What can make your million dollar SIEM go blind?
DCShadow explained: A technical deep dive into the latest AD attack technique
Name: Rogue Domain Controllers
Codename: C-DCSHADOW
Severity: High
Benjamin Delpy: Mimikatz - DCShadow module