Hub
Identity

ALD Pro domain controller

About 61,200 selected records/day from one domain controller, including native KDC, LDAP access and audit records.

Quick Start

uv tool install eventum-generator
git clone https://github.com/eventum-generator/content-packs.git
cd content-packs
eventum generate \
  --path generators/identity-ald-pro/generator.yml \
  --id ald-pro \
  --live-mode true

Event Types

Event IDDescriptionFrequencyCategory
AS_REQ NEEDED_PREAUTH / ISSUEPreauthentication challenge and successful TGT issuanceSelected workloadauthentication
TGS_REQ ISSUEService tickets using an already observed TGTSelected workloadauthentication
AS_REQ PREAUTH_FAILEDIsolated failures and periodic password spraySelected workloadauthentication
SSL connection, TLS, UNBIND, clean disconnectAdministrative LDAP sessionsSelected workloadiam
GSSAPI BIND / RESULTThree rounds: op 0/1 return err 14, op 2 succeedsSelected workloadiam
MOD / RESULTSuccessful changes to existing groups or SUDO rulesSelected workloadiam
Add / delete member LDIFMembership changes and restorationSelected workloadiam
Replace / delete cmdCategory LDIFSUDO activation and restorationSelected workloadiam
Replace description LDIFOrdinary policy maintenanceSelected workloadiam

Realism Features

  • Human working hours follow UTC+03:00; service accounts continue overnight
  • LDAP negotiation, changes and restorations retain their request and actor relationships
  • Selected vendor guide profile; exact bundled versions and raw SUDO parity are unconfirmed

Sample Output

{
  "@timestamp": "2026-09-20T01:03:03.401103+00:00",
  "aldpro": {
    "dirsrv": {
      "audit": {
        "attribute": "cmdCategory",
        "attribute_operation": "replace",
        "attribute_value": "all",
        "changetype": "modify",
        "dn": "ipauniqueid=a4a19e36-4c0c-4d2f-97aa-e7fe42aa6ae4,cn=sudorules,cn=sudo,dc=lab,dc=example",
        "entryusn": 100002,
        "modifiersname": "uid=directory.admin,cn=users,cn=accounts,dc=lab,dc=example",
        "modifytimestamp": "20260920010303Z",
        "object_name": "operations-3",
        "result": 0,
        "time": "20260920040303"
      }
    }
  },
  "ecs": {
    "version": "8.11.0"
  },
  "event": {
    "action": "replace-cmdCategory",
    "category": [
      "iam"
    ],
    "dataset": "aldpro.dirsrv_audit",
    "kind": "event",
    "module": "aldpro",
    "original": "time: 20260920040303\ndn: ipauniqueid=a4a19e36-4c0c-4d2f-97aa-e7fe42aa6ae4,cn=sudorules,cn=sudo,dc=lab,dc=example\nresult: 0\nchangetype: modify\nreplace: cmdCategory\ncmdCategory: all\n-\nreplace: modifiersname\nmodifiersname: uid=directory.admin,cn=users,cn=accounts,dc=lab,dc=example\n-\nreplace: modifytimestamp\nmodifytimestamp: 20260920010303Z\n-\nreplace: entryusn\nentryusn: 100002\n-\n\n",
    "outcome": "success",
    "type": [
      "change"
    ]
  },
  "host": {
    "name": "dc-1.lab.example"
  },
  "log": {
    "file": {
      "path": "/var/log/dirsrv/slapd-LAB-EXAMPLE/audit"
    }
  },
  "message": "time: 20260920040303\ndn: ipauniqueid=a4a19e36-4c0c-4d2f-97aa-e7fe42aa6ae4,cn=sudorules,cn=sudo,dc=lab,dc=example\nresult: 0\nchangetype: modify\nreplace: cmdCategory\ncmdCategory: all\n-\nreplace: modifiersname\nmodifiersname: uid=directory.admin,cn=users,cn=accounts,dc=lab,dc=example\n-\nreplace: modifytimestamp\nmodifytimestamp: 20260920010303Z\n-\nreplace: entryusn\nentryusn: 100002\n-\n\n",
  "related": {
    "user": [
      "directory.admin"
    ]
  },
  "source": {
    "ip": "10.20.4.22"
  },
  "user": {
    "domain": "LAB.EXAMPLE",
    "name": "directory.admin"
  }
}

Parameters

ParameterDefaultDescription
dc_hostdc-1.lab.exampleSource hostname and LDAP service principal host
realmLAB.EXAMPLEKerberos realm
base_dndc=lab,dc=exampleExisting LDAP suffix
directory_instanceLAB-EXAMPLE389 DS instance in paths
attack_ip10.99.8.42Client shared by ordinary activity and episodes
compromised_userhelpdesk.adminExisting administrator shared with background
added_usersvc_syncExisting account whose membership changes
privileged_groupadminsExisting group display name / DN component
sudo_rulemaintenanceExisting rule display name, inventory enrichment
ecs_version8.11.0ECS version
anomaly_modetruePeriodic episodes mixed with background; false is background only
routine_admindirectory.adminSecond existing administrator
admin_ip10.20.4.22Second ordinary administrative client
sudo_rule_uuida4a19e36-4c0c-4d2f-97aa-e7fe42aa6ae1Existing rule's native `ipauniqueid` RDN
anomaly_interval_hours24Recurrence, values below 6 clamp to 6 hours
dc_ip10.20.0.10Native LDAP connection destination

Related Generators