Kroll published detection guidance for CVE-2020-1472 (Zerologon), the critical Microsoft Netlogon flaw that allows attackers to compromise Active Directory domain controllers. The guidance followed Microsoft's advisory and focused on identifying whether attackers had already abused the bug in the wild, a risk highlighted by warnings from Microsoft, DHS, and the FBI, including reports of active exploitation by state-backed actors.
The detection playbook describes three common attack paths: resetting a domain controller computer-account password and leaving it changed, resetting it and later restoring the original password, and using a printer spooler plus NTLM relay technique that avoids a password reset entirely. Kroll said defenders should review Windows security events including 4624, 4742, and in some cases 5805, examine domain controller password-hash history for null-password resets or restored credentials, inspect LSASS memory with Yara-based methods, and use Snort or Suricata to spot scans and exploitation attempts on the network.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Mimikatz release 2.2.0 #19041 added a module to scan for and exploit Zerologon, expanding public offensive tooling for the vulnerability.
DHS issued an urgent directive on September 18 requiring systems to be patched by September 21. The article also says the FBI and Microsoft warned of active exploitation, including against networks supporting election systems and by state-sponsored hackers.
The Emerging Threats public Snort rules repository released a rule to detect Zerologon exploitation attempts by identifying repeated NetrServerAuthenticate requests with 0x00 client credentials.
Microsoft issued a patch for CVE-2020-1472, also known as Zerologon, a critical Active Directory domain controller vulnerability that can let an unauthenticated attacker gain the highest privileges in a domain.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.