Case 44A5DD · Blue team / DFIR · L3 Applied
Security Log Wiped on a DC
Practise as: Incident drill
Live alertThe SIEM receives event 1102 (audit log cleared) from domain controller DC-01 at 23:51, attributed to svc_backup, an account that never logs on interactively.
- 01 What happened?
- 02 What is the impact?
- 03 What do you do?
What a strong answer covers
Try it out loud first. Then check yourself:
- Log clearing on a DC is anti-forensics (T1070.001) and implies prior admin-level compromise; treat as critical.
- Forwarded SIEM copies survive the wipe: reconstruct svc_backup activity from 4624/4672/4688 events before 23:51.
- Check for DCSync (4662 with replication GUIDs), new admins (4728/4732) and GPO changes.
- Disable svc_backup, rotate its credentials, and hunt where else it authenticated recently.
- If domain compromise is confirmed, plan a krbtgt double reset and a coordinated eviction.
If the interviewer pushes back
- How would you detect DCSync from a non-DC host using both host and network telemetry?
Go deeper
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.