{
  "technique_id": "T1207",
  "name": "Rogue Domain Controller",
  "tactics": [
    "Defense Impairment"
  ],
  "platforms": [
    "Windows"
  ],
  "summary": "Adversaries may register a rogue Domain Controller to enable manipulation of Active Directory data. DCShadow may be used to create a rogue Domain Controller (DC). DCShadow is a method of manipulating Active Directory (AD) data, including objects and schemas, by registering (or reusing an inactive registration) and simulating the behavior of a DC. Once registered, a rogue DC may be able to inject and replicate changes into AD infrastructure for any domain object, including credentials and keys...",
  "generated_by": "SOC Response Atlas by Basyrix"
}