Synopsis
Activation Period |
14 Days |
Training Period |
30 Days |
Test Period |
N/A (single event) |
Deduplication Period |
1 Day |
Required Data |
|
Detection Modules |
Identity Analytics |
Detector Tags |
Active Directory Certificate Services Analytics |
ATT&CK Tactic |
|
ATT&CK Technique |
|
Severity |
Low |
Description
Suspicious account attribute modification that matches that of another account.
Attacker's Goals
An attacker might modify account attributes to elevate privileges and get access to strong accounts in the domain.
Investigative actions
- Check if any associated certificates were granted.
- Check if any login attempts were made by the impersonated accounts using certificates.
- Check if any Kerberos TGT tickets were generated by the impersonated accounts using certificates.