Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters. tactic: TA0006 ✕

Download CSV Show ATT&CK heatmap
  • Suspicious certificate template modification Informational Identity Analytics 2 variations

    A certificate template was updated with a possible misconfiguration. This may indicate the exploitation of misconfigured certificate template access control (ESC4).

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Hour
    ATT&CK tactics: Credential Access (TA0006)
    ATT&CK techniques: Steal or Forge Authentication Certificates (T1649)
    Required data: Windows Event Collector XDR Agent with eXtended Threat Hunting (XTH)
    Detector tags: Active Directory Certificate Services Analytics
    Attacker's goals: An attacker is attempting to exploit AD CS misconfigurations to obtain certificates that can be used for credential theft and privilege escalation.
    Investigative actions: Review the AD CS configuration for vulnerable templates and EKU settings.* Review AD CS logs to identify any unauthorized certificate issuances, modifications, or template changes.

    Variations

    Certificate template was updated to be vulnerable to AD CS ESC attack

    Medium overridden

    A certificate template was updated, making it vulnerable to an AD CS ESC attack. This may indicate the potential abuse of AD CS ESC4. overridden

    Certificate template was updated with a misconfiguration configuration

    Low overridden

    A certificate template was updated with new misconfiguration. This may indicate a potential AD CS ESC4 attack. overridden