MITRE ATT&CK technique
Rogue Domain Controller detection rulesT1207
Rogue Domain Controller (T1207) is a MITRE ATT&CK technique in the Defense Impairment tactic. This page lists the 2 community-maintained Sigma detection rules in the library mapped to T1207 and its sub-techniques. Each rule includes its detection logic, log source, false positives and original YAML. These rules mainly target windows.
T1207 on attack.mitre.org2 rules