Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters. tactic: TA0007 ✕ technique: T1083 ✕
Download CSV Show ATT&CK heatmapDiscovery of misconfigured certificate templates using LDAP Medium 1 variation
An LDAP query searching for misconfigured certificate templates was executed.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Discovery (TA0007)ATT&CK techniques: File and Directory Discovery (T1083)Required data: XDR Agent with eXtended Threat Hunting (XTH)Detector tags: LDAP Analytics (Client), LDAP Analytics (Server), Active Directory Certificate Services AnalyticsAttacker's goals: An attacker can use misconfigured certificate templates for escalation and authentication.Investigative actions: Check if the LDAP search query was allowed for the user (logged on at event time) or process. Investigate the LDAP search query for any suspicious indicators.Variations
Frequent LDAP discovery of misconfigured certificate templates by a common process
Low overridden
An LDAP query searching for misconfigured certificate templates was executed regularly by a common process. overridden