Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source
  • Possible Privilege Escalation using Delegated MSA account Informational Identity Analytics 1 variation

    An attacker might abuse dMSA account to escalate its privileges.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    1 Hour
    Deduplication:
    1 Day
    ATT&CK tactics: Privilege Escalation (TA0004)
    ATT&CK techniques: Account Manipulation (T1098)
    Required data: Windows Event Collector XDR Agent with eXtended Threat Hunting (XTH)
    Attacker's goals: Attackers may leverage dMSA account migration process to escalate privileges.
    Investigative actions: Confirm that the user is authorized to create and modify dMSA accounts in the domain. Verify the user should have permissions on the OU under which the dMSA account was created. Validate that the dMSA account should be created under the OU that appeared in the log (use the GUID). Verify that the user superseded an account, with the dMSA account, that should have superseded. Check the GUID of the dMSA object to get the account itself (can be viewed also in computer account creation event). Check what is the superseded account in the attribute 'msDS-ManagedAccountPrecededByLink' of the dMSA object. Investigate the host that initiated the dMSA account migration process for malicious activity.

    Variations

    Possible Privilege Escalation using Delegated MSA account attempt

    Medium overridden

    An attacker might abuse dMSA account to escalate its privileges. overridden