ALD Pro domain controller
About 61,200 selected records/day from one domain controller, including native KDC, LDAP access and audit records.
Quick Start
uv tool install eventum-generator
git clone https://github.com/eventum-generator/content-packs.git
cd content-packs
eventum generate \
--path generators/identity-ald-pro/generator.yml \
--id ald-pro \
--live-mode trueEvent Types
| Event ID | Description | Frequency | Category |
|---|---|---|---|
| AS_REQ NEEDED_PREAUTH / ISSUE | Preauthentication challenge and successful TGT issuance | Selected workload | authentication |
| TGS_REQ ISSUE | Service tickets using an already observed TGT | Selected workload | authentication |
| AS_REQ PREAUTH_FAILED | Isolated failures and periodic password spray | Selected workload | authentication |
| SSL connection, TLS, UNBIND, clean disconnect | Administrative LDAP sessions | Selected workload | iam |
| GSSAPI BIND / RESULT | Three rounds: op 0/1 return err 14, op 2 succeeds | Selected workload | iam |
| MOD / RESULT | Successful changes to existing groups or SUDO rules | Selected workload | iam |
| Add / delete member LDIF | Membership changes and restoration | Selected workload | iam |
| Replace / delete cmdCategory LDIF | SUDO activation and restoration | Selected workload | iam |
| Replace description LDIF | Ordinary policy maintenance | Selected workload | iam |
Realism Features
- Human working hours follow UTC+03:00; service accounts continue overnight
- LDAP negotiation, changes and restorations retain their request and actor relationships
- Selected vendor guide profile; exact bundled versions and raw SUDO parity are unconfirmed
Sample Output
{
"@timestamp": "2026-09-20T01:03:03.401103+00:00",
"aldpro": {
"dirsrv": {
"audit": {
"attribute": "cmdCategory",
"attribute_operation": "replace",
"attribute_value": "all",
"changetype": "modify",
"dn": "ipauniqueid=a4a19e36-4c0c-4d2f-97aa-e7fe42aa6ae4,cn=sudorules,cn=sudo,dc=lab,dc=example",
"entryusn": 100002,
"modifiersname": "uid=directory.admin,cn=users,cn=accounts,dc=lab,dc=example",
"modifytimestamp": "20260920010303Z",
"object_name": "operations-3",
"result": 0,
"time": "20260920040303"
}
}
},
"ecs": {
"version": "8.11.0"
},
"event": {
"action": "replace-cmdCategory",
"category": [
"iam"
],
"dataset": "aldpro.dirsrv_audit",
"kind": "event",
"module": "aldpro",
"original": "time: 20260920040303\ndn: ipauniqueid=a4a19e36-4c0c-4d2f-97aa-e7fe42aa6ae4,cn=sudorules,cn=sudo,dc=lab,dc=example\nresult: 0\nchangetype: modify\nreplace: cmdCategory\ncmdCategory: all\n-\nreplace: modifiersname\nmodifiersname: uid=directory.admin,cn=users,cn=accounts,dc=lab,dc=example\n-\nreplace: modifytimestamp\nmodifytimestamp: 20260920010303Z\n-\nreplace: entryusn\nentryusn: 100002\n-\n\n",
"outcome": "success",
"type": [
"change"
]
},
"host": {
"name": "dc-1.lab.example"
},
"log": {
"file": {
"path": "/var/log/dirsrv/slapd-LAB-EXAMPLE/audit"
}
},
"message": "time: 20260920040303\ndn: ipauniqueid=a4a19e36-4c0c-4d2f-97aa-e7fe42aa6ae4,cn=sudorules,cn=sudo,dc=lab,dc=example\nresult: 0\nchangetype: modify\nreplace: cmdCategory\ncmdCategory: all\n-\nreplace: modifiersname\nmodifiersname: uid=directory.admin,cn=users,cn=accounts,dc=lab,dc=example\n-\nreplace: modifytimestamp\nmodifytimestamp: 20260920010303Z\n-\nreplace: entryusn\nentryusn: 100002\n-\n\n",
"related": {
"user": [
"directory.admin"
]
},
"source": {
"ip": "10.20.4.22"
},
"user": {
"domain": "LAB.EXAMPLE",
"name": "directory.admin"
}
}Parameters
| Parameter | Default | Description |
|---|---|---|
| dc_host | dc-1.lab.example | Source hostname and LDAP service principal host |
| realm | LAB.EXAMPLE | Kerberos realm |
| base_dn | dc=lab,dc=example | Existing LDAP suffix |
| directory_instance | LAB-EXAMPLE | 389 DS instance in paths |
| attack_ip | 10.99.8.42 | Client shared by ordinary activity and episodes |
| compromised_user | helpdesk.admin | Existing administrator shared with background |
| added_user | svc_sync | Existing account whose membership changes |
| privileged_group | admins | Existing group display name / DN component |
| sudo_rule | maintenance | Existing rule display name, inventory enrichment |
| ecs_version | 8.11.0 | ECS version |
| anomaly_mode | true | Periodic episodes mixed with background; false is background only |
| routine_admin | directory.admin | Second existing administrator |
| admin_ip | 10.20.4.22 | Second ordinary administrative client |
| sudo_rule_uuid | a4a19e36-4c0c-4d2f-97aa-e7fe42aa6ae1 | Existing rule's native `ipauniqueid` RDN |
| anomaly_interval_hours | 24 | Recurrence, values below 6 clamp to 6 hours |
| dc_ip | 10.20.0.10 | Native LDAP connection destination |
Related Generators
Keycloak 26.7.4 Event Log
Keycloak 26.7.4 jboss-logging user and admin event lines for one realm with 1,500 users and 5 administrators, as native text in event.original with keycloak.*, user.*, source.* and url.* fields following the Elastic keycloak.log pipeline. Recurring episodes show one administrator failing five to eight logins from a VPN egress address, then logging in to the admin console and granting a privileged realm role.
Active Directory audit
About 21,800 normalized Security records per day from a small domain, with Kerberos, NTLM and temporary group membership.
Cisco ISE 3.4 Administrative Audit Syslog
Cisco ISE CISE_Administrative_and_Operational_Audit remote syslog and matching ECS-style JSON for one Policy Administration Node, with the complete syslog record in event.original, for detections on ISE administrator activity. Logins, logoffs and failed logins of five administrators and 120 read-only operators, and logging-configuration changes; not RADIUS or TACACS traffic. Weekly episodes show an administrator account taken over by password guessing and used to switch off log forwarding.