Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters. tactic: TA0006 ✕ technique: T1556 ✕
Download CSV Show ATT&CK heatmapKey credential attribute modification Informational Identity Analytics 2 variations
A user modified the msDS-KeyCredentialLink attribute for an account, which may indicate a shadow credentials attack.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Credential Access (TA0006)ATT&CK techniques: Modify Authentication Process (T1556)Required data: Windows Event Collector XDR Agent with eXtended Threat Hunting (XTH)Detector tags: Active Directory Certificate Services AnalyticsAttacker's goals: An attacker may be attempting to add shadow credentials to an account, gaining persistent unauthorized access.Investigative actions: Follow further PKINIT authentication activity by the modified identity.* Verify if Windows Hello for Business is enabled, as this is a common benign cause for this activity.* Check if the modified credential maps to an existing device ID in Entra ID.* Examine recent activity from the user account, including logon patterns and privilege changes.Variations
Possible shadow credentials addition
Medium overridden
A user modified the msDS-KeyCredentialLink attribute for an account, which may indicate a shadow credentials attack. overridden
Key credential attribute addition
Low overridden
A user modified the msDS-KeyCredentialLink attribute for an account, which may indicate a shadow credentials attack. overridden