← Back to feed
Vendors & MarketEmerging1 sourceJan 15, 2026 · 15:00via Huntress Blog

SDFlags | Huntress

Brief

While investigating LDAP filters and attributes, I completely missed "SDFlags" in my Event 1644 logs. When I finally noticed it, the investigation led to nTSecurityDescriptor, attack path discovery, and a high-confidence detection signature.

Read more on Huntress Blog