Open cardosec

Case 44A5DD · Blue team / DFIR · L3 Applied

Security Log Wiped on a DC

Practise as: Incident drill

Live alertThe SIEM receives event 1102 (audit log cleared) from domain controller DC-01 at 23:51, attributed to svc_backup, an account that never logs on interactively.

  1. 01 What happened?
  2. 02 What is the impact?
  3. 03 What do you do?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. Log clearing on a DC is anti-forensics (T1070.001) and implies prior admin-level compromise; treat as critical.
  2. Forwarded SIEM copies survive the wipe: reconstruct svc_backup activity from 4624/4672/4688 events before 23:51.
  3. Check for DCSync (4662 with replication GUIDs), new admins (4728/4732) and GPO changes.
  4. Disable svc_backup, rotate its credentials, and hunt where else it authenticated recently.
  5. If domain compromise is confirmed, plan a krbtgt double reset and a coordinated eviction.

If the interviewer pushes back

  • How would you detect DCSync from a non-DC host using both host and network telemetry?

Go deeper

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.