Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters.
Download CSV Show ATT&CK heatmapSuspicious certificate template modification Informational Identity Analytics 2 variations
A certificate template was updated with a possible misconfiguration. This may indicate the exploitation of misconfigured certificate template access control (ESC4).
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Hour
ATT&CK tactics: Credential Access (TA0006)ATT&CK techniques: Steal or Forge Authentication Certificates (T1649)Required data: Windows Event Collector XDR Agent with eXtended Threat Hunting (XTH)Detector tags: Active Directory Certificate Services AnalyticsAttacker's goals: An attacker is attempting to exploit AD CS misconfigurations to obtain certificates that can be used for credential theft and privilege escalation.Investigative actions: Review the AD CS configuration for vulnerable templates and EKU settings.* Review AD CS logs to identify any unauthorized certificate issuances, modifications, or template changes.Variations
Certificate template was updated to be vulnerable to AD CS ESC attack
Medium overridden
A certificate template was updated, making it vulnerable to an AD CS ESC attack. This may indicate the potential abuse of AD CS ESC4. overridden
Certificate template was updated with a misconfiguration configuration
Low overridden
A certificate template was updated with new misconfiguration. This may indicate a potential AD CS ESC4 attack. overridden