Analytics BIOC
Medium
✕
Discovery of misconfigured certificate templates using LDAP
An LDAP query searching for misconfigured certificate templates was executed.
- Module:
- Platform Analytics
- Data source:
- XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Discovery (TA0007)
ATT&CK techniques: File and Directory Discovery (T1083)
Detector tags: LDAP Analytics (Client) LDAP Analytics (Server) Active Directory Certificate Services Analytics
Attacker's goals:
An attacker can use misconfigured certificate templates for escalation and authentication.
Investigative actions:
Check if the LDAP search query was allowed for the user (logged on at event time) or process. Investigate the LDAP search query for any suspicious indicators.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
1 variation:
- Frequent LDAP discovery of misconfigured certificate templates by a common process Low (parent: Medium)