Analytics BIOC
Informational
✕
Key credential attribute modification
A user modified the msDS-KeyCredentialLink attribute for an account, which may indicate a shadow credentials attack.
- Module:
- Identity Analytics
- Data source:
- Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Credential Access (TA0006)
ATT&CK techniques: Modify Authentication Process (T1556)
Detector tags: Active Directory Certificate Services Analytics
Attacker's goals:
An attacker may be attempting to add shadow credentials to an account, gaining persistent unauthorized access.
Investigative actions:
Follow further PKINIT authentication activity by the modified identity.* Verify if Windows Hello for Business is enabled, as this is a common benign cause for this activity.* Check if the modified credential maps to an existing device ID in Entra ID.* Examine recent activity from the user account, including logon patterns and privilege changes.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
2 variations:
- Possible shadow credentials addition Medium (parent: Informational)
- Key credential attribute addition Low (parent: Informational)