Zerologon (CVE-2020-1472) DC Machine Account Reset / Netlogon Anomaly
Detects potential exploitation attempts of the Zerologon vulnerability (CVE-2020-1472) by monitoring for Domain Controller machine account password resets (Event 4742) targeting DC computer accounts, and insecure Netlogon RPC channel events (Event 5829) triggered when vulnerable clients or tools attempt connections.
Splunk (SPL)

