Dynamic Objects Misconfiguration and Usage

medium

Description

Detects dynamic objects and insecure Time-To-Live (TTL) configurations that allow attackers to create stealthy, self-destructing backdoors to evade standard auditing and forensic analysis.

Solution

Immediately manually delete suspicious dynamic objects to prevent forensic evasion, and restore msDS-Other-Settings TTL values to secure defaults (900 and 86400 seconds) to block ephemeral attacks

See Also

Dynamic Objects

AD Object Detection: Detecting the undetectable (dynamicObject)

fun with dynamic Objects in AD: Part 1

Indicator Details

Name: Dynamic Objects Misconfiguration and Usage

Codename: C-DYNAMIC-OBJECTS

Severity: Medium

Type: Active Directory Indicator of Exposure

Family: Hygiene and Lifecycle

MITRE ATT&CK Information: