Analytics BIOC Low

A user modified the CA audit policy

A user modified the CA audit policy. This may indicate that an attacker is attempting to cover their tracks before an AD CS attack.

Module:
Identity Analytics
Data source:
Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Defense Evasion (TA0005)
ATT&CK techniques: Impair Defenses: Disable Windows Event Logging (T1562.002)
Detector tags: Active Directory Certificate Services Analytics
Attacker's goals:

An attacker is attempting to cover their tracks before an AD CS attack.

Investigative actions:

Check the user account modifying the CA audit policy and verify its activity. Review AD CS logs to identify any unauthorized certificate issuances, modifications, or template changes. Examine recent activity from the user account, including logon patterns and privilege changes. Continue monitoring the account for any subsequent actions that may indicate suspicious behavior.

Test period:
N/A (single event)
Deduplication:
1 Day