Potential RID Hijacking Attempt

Rule Info

Name
Potential RID Hijacking Attempt
Author
Swachchhanda Shrawn Poudel (Nextron Systems)
Description
Detects attempts to modify the SAM registry to potentially perform RID hijacking attacks. In a RID hijacking attack, an attacker modifies the RID set of a user account like guest user to escalate privileges or impersonate another user.
Date
2026-05-19 00:00:00
Modified
None
Id
059d9ab9-e3d6-4b7b-bb58-3fb09f381122
Tags
attack.privilege-escalation attack.persistence attack.t1098
Type
Nextron Sigma feed only (private)

Rule History