It seems like your browser didn't download the required fonts. Please revise your security settings and try again.
Barracuda XDR

Simulating Log Monitoring Threats

  • Last updated on

The use case for this test is Privilege Escalation—Add a user to the Domain Admins Group.

Privilege Escalation is a common way for an attacker to gain unauthorized asses to a system/account. In many cases that first point of attack will not grant attackers with the level of access they need. They will then attempt privilege escalation to gain more permissions or obtain access to additional, more sensitive systems.

Log Monitoring 1.png

How to Test

Testing is only for clients which WMI logs are being monitored. This activity can only be done by a Local Admin or a Domain Admin. There are usually very few admin users  chosen within an organization, so these actions should be closely monitored for any  unauthorized activity.

  1. Open Start > Computer Management > Local Users and Groups.
  2. Click on Users, right-click on the user and click Properties.
    Log Monitoring 2.png
  3. On the Member Of tab, click Add.
    Log Monitoring 3.png
  4. Click Advanced, then Find Now.
  5. Look for Domain Admins in the search results. Click OK.
    Log Monitoring 4.png
  6. This adds the user to the Domain Admins group. Click OK.
    Log Monitoring 5.png
  7. Click Advanced, then Find Now.
  8. Look for Domain Admins in the search results. Click OK.