Analytics BIOC Medium

Discovery of misconfigured certificate templates using LDAP

An LDAP query searching for misconfigured certificate templates was executed.

Module:
Platform Analytics
Data source:
XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Discovery (TA0007)
ATT&CK techniques: File and Directory Discovery (T1083)
Detector tags: LDAP Analytics (Client) LDAP Analytics (Server) Active Directory Certificate Services Analytics
Attacker's goals:

An attacker can use misconfigured certificate templates for escalation and authentication.

Investigative actions:

Check if the LDAP search query was allowed for the user (logged on at event time) or process. Investigate the LDAP search query for any suspicious indicators.

Test period:
N/A (single event)
Deduplication:
1 Day
1 variation:
  • Frequent LDAP discovery of misconfigured certificate templates by a common process Low (parent: Medium)