Kroll published detection guidance for CVE-2020-1472 (Zerologon), the critical Microsoft Netlogon flaw that allows attackers to compromise Active Directory domain controllers. The guidance followed Microsoft's advisory and focused on identifying whether attackers had already abused the bug in the wild, a risk highlighted by warnings from Microsoft, DHS, and the FBI, including reports of active exploitation by state-backed actors.
The detection playbook describes three common attack paths: resetting a domain controller computer-account password and leaving it changed, resetting it and later restoring the original password, and using a printer spooler plus NTLM relay technique that avoids a password reset entirely. Kroll said defenders should review Windows security events including 4624, 4742, and in some cases 5805, examine domain controller password-hash history for null-password resets or restored credentials, inspect LSASS memory with Yara-based methods, and use Snort or Suricata to spot scans and exploitation attempts on the network.

See which actors are running it and whether you're in range.
6 events from the most recent confirmed update back to the earliest known activity.
Microsoft's second-phase mitigation for CVE-2020-1472 began on 2021-02-09, enforcing secure RPC on all domain controllers regardless of the prior registry setting. The phase also changed logging behavior so insecure RPC connections were denied and logged as Event ID 5827, with only explicitly exempted devices allowed to continue.
Mimikatz release 2.2.0 #19041 added a module to scan for and exploit Zerologon, expanding public offensive tooling for the vulnerability.
DHS issued an urgent directive on September 18 requiring systems to be patched by September 21. The article also says the FBI and Microsoft warned of active exploitation, including against networks supporting election systems and by state-sponsored hackers.
Microsoft released the initial deployment-phase updates for CVE-2020-1472 on August 11, 2020, beginning phased enforcement of secure RPC for Netlogon secure channel connections. The updates added logging and temporary exception controls to identify and manage non-compliant devices before mandatory enforcement.
The Emerging Threats public Snort rules repository released a rule to detect Zerologon exploitation attempts by identifying repeated NetrServerAuthenticate requests with 0x00 client credentials.
Microsoft issued a patch for CVE-2020-1472, also known as Zerologon, a critical Active Directory domain controller vulnerability that can let an unauthenticated attacker gain the highest privileges in a domain.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
4 references tracked. Mallory keeps watching after this page renders.
mnemonic.io
Open sourcekroll.com
Open sourceportal.msrc.microsoft.com
Open sourcesupport.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.