Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters.

Download CSV Show ATT&CK heatmap
  • Key credential attribute modification Informational Identity Analytics 2 variations

    A user modified the msDS-KeyCredentialLink attribute for an account, which may indicate a shadow credentials attack.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Credential Access (TA0006)
    ATT&CK techniques: Modify Authentication Process (T1556)
    Required data: Windows Event Collector XDR Agent with eXtended Threat Hunting (XTH)
    Detector tags: Active Directory Certificate Services Analytics
    Attacker's goals: An attacker may be attempting to add shadow credentials to an account, gaining persistent unauthorized access.
    Investigative actions: Follow further PKINIT authentication activity by the modified identity.* Verify if Windows Hello for Business is enabled, as this is a common benign cause for this activity.* Check if the modified credential maps to an existing device ID in Entra ID.* Examine recent activity from the user account, including logon patterns and privilege changes.

    Variations

    Possible shadow credentials addition

    Medium overridden

    A user modified the msDS-KeyCredentialLink attribute for an account, which may indicate a shadow credentials attack. overridden

    Key credential attribute addition

    Low overridden

    A user modified the msDS-KeyCredentialLink attribute for an account, which may indicate a shadow credentials attack. overridden