Rule Info
Name
Potential RID Hijacking Attempt
Author
Swachchhanda Shrawn Poudel (Nextron Systems)
Description
Detects attempts to modify the SAM registry to potentially perform RID hijacking attacks.
In a RID hijacking attack, an attacker modifies the RID set of a user account like guest user to escalate privileges or impersonate another user.
Date
2026-05-19 00:00:00
Modified
None
Id
059d9ab9-e3d6-4b7b-bb58-3fb09f381122
Tags
attack.privilege-escalation attack.persistence attack.t1098
Type
Nextron Sigma feed only (private)
