Windows AD DCShadow Privileges ACL Addition — Detection Rule

This detection identifies an Active Directory access-control list (ACL) modification event, which applies the minimum required extended rights to perform the DCShadow attack.

Read the full analysis on IntelFusions