{"repo":"ANSSI-FR/ADTimeline","free":true,"listed":false,"github":"https://github.com/ANSSI-FR/ADTimeline","clone":"git clone https://github.com/ANSSI-FR/ADTimeline.git","description":"Timeline of Active Directory changes with replication metadata","language":"PowerShell","stars":534,"topics":["windows","forensics","dfir","active-directory","powershell","timeline","splunk"],"license":"GPL-3.0","category":"dashboards-admin","readme_excerpt":"--- Table of contents: 1. The ADTimeline PowerShell script 1. Description 2. Prerequisites 3. Usage 4. Files generated 5. Custom groups 2. The ADTimeline App for Splunk 1. Description 2. Sourcetypes 3. AD General information dashboards 4. AD threat hunting dashboards 5. Enhance your traditional event logs threat hunting with ADTimeline The ADTimeline PowerShell script: Description: The ADTimeline script generates a timeline based on Active Directory replication metadata for objects considered of interest. Replication metadata gives you the time at which each replicated attribute for a given object was last changed. As a result the timeline of modifications is partial. For each modification of a replicated attribute a version number is incremented. ADTimeline was first presented at the CoRI&IN 2019 (Conférence sur la réponse aux incidents et l’investigation numérique). Slides of the presentation, in french language, are available here. It was also presented at the Amsterdam 2019 FIRST Technical Colloquium, slides in english are available here. Objects considered of interest retrieved by the script include: - Schema and configuration partition root objects. - Domain root and objects located directly under the root. - Objects having an ACE on the domain root. - Domain roots located in the AD forest. - Domain trusts. - Deleted users (i.e. tombstoned). - Objects protected by the SDProp process (i.e. AdminCount equals 1). - The Guest account. - The AdminSDHolder object. - Objects h","default_branch":null,"files":null,"tree":[],"storefront":"/r/ANSSI-FR","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/ANSSI-FR/ADTimeline/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}