Analytics Informational

A user logged on to multiple workstations via Schannel

A user logged on to multiple workstations with a certificate via Schannel. This may be indicative of a compromised account.

Module:
Identity Analytics
Data source:
XDR Agent
ATT&CK tactics: Persistence (TA0003) Privilege Escalation (TA0004) Credential Access (TA0006)
ATT&CK techniques: Account Manipulation (T1098) Valid Accounts (T1078) Steal or Forge Authentication Certificates (T1649)
Detector tags: Active Directory Certificate Services Analytics
Attacker's goals:

Elevate permissions and establish persistence.

Investigative actions:

Verify the activity with the performing user. Check for possible certificate authentications with the subject user. Check if the user logged in to other endpoints via Schannel.

Test period:
1 Hour
Deduplication:
1 Day
2 variations:
  • Rare user authentication with a certificate via Schannel Low (parent: Informational)
  • Abnormal authentication with a certificate via Schannel Informational