A security operations center (SOC) analyst is investigating an alert generated by Microsoft Defender for Identity concerning a 'Suspicious service creation' on a domain controller. The alert details indicate that an attacker successfully created a new service, potentially for persistence. Which specific type of sensor deployed on the domain controller is responsible for detecting this activity?
- AMicrosoft Sentinel Data Connector
- BMicrosoft Defender for Cloud Apps App Connector
- CMicrosoft Defender for Endpoint sensor
- DMicrosoft Defender for Identity Lightweight Sensor
Show answer & explanationAnswer & explanation
Correct answer: D. Microsoft Defender for Identity Lightweight Sensor
Microsoft Defender for Identity uses a Lightweight Sensor deployed directly on domain controllers to monitor network traffic and Windows events, specifically for detecting suspicious activities like service creation that indicate potential compromise or malicious intent within the identity infrastructure. Defender for Endpoint sensors are for client devices, and Cloud Apps connectors and Sentinel data connectors are for different purposes.
Why the other options are wrong
- A. Microsoft Sentinel Data Connectors ingest data from various sources into Sentinel, but they are not the *source* of the detection itself in this context; Defender for Identity is.
- B. Defender for Cloud Apps App Connectors integrate with cloud applications to monitor user activities and data, unrelated to on-premises domain controller security.
- C. Defender for Endpoint sensors monitor client devices and servers for endpoint-level threats, not specifically identity-related activities on domain controllers.
Defender for Identity Lightweight Sensor
The Microsoft Defender for Identity Lightweight Sensor is deployed directly on domain controllers to monitor network traffic and Windows events for identity-based threats and suspicious activities.
- Installed on domain controllers.
- Monitors NTLM, Kerberos, DNS, RPC, and other network traffic.
- Collects Windows Events (e.g., security event logs).
- Detects identity-based attacks like Golden Ticket, Pass-the-Hash, suspicious service creation.
Memory trick: Remember, the 'Identity' 'Sensor' is 'Lightweight' but 'Heavy' on 'Domain Controller' 'Eyes'.