Analytics BIOC
Informational
✕
A user queried AD CS objects via LDAP
A user queried AD CS objects via LDAP.
- Module:
- Identity Analytics
- Data source:
- XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Discovery (TA0007) Credential Access (TA0006)
ATT&CK techniques: File and Directory Discovery (T1083) Steal or Forge Authentication Certificates (T1649)
Detector tags: LDAP Analytics (Server) Active Directory Certificate Services Analytics
Attacker's goals:
An attacker might look for AD CS servers, certificate templates or request certificates. With the wrong setting or loose vulnerable templates or enabled enrollment, the attacker will be able to authenticate as users on the network.
Investigative actions:
Check if the LDAP search query was allowed for the user (logged on at event time). Investigate the LDAP search query for any suspicious indicators.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
1 variation:
- A user enumerated AD CS objects using suspicious LDAP query Low (parent: Informational)