Analytics BIOC Informational

Key credential attribute modification

A user modified the msDS-KeyCredentialLink attribute for an account, which may indicate a shadow credentials attack.

Module:
Identity Analytics
Data source:
Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Credential Access (TA0006)
ATT&CK techniques: Modify Authentication Process (T1556)
Detector tags: Active Directory Certificate Services Analytics
Attacker's goals:

An attacker may be attempting to add shadow credentials to an account, gaining persistent unauthorized access.

Investigative actions:

Follow further PKINIT authentication activity by the modified identity.* Verify if Windows Hello for Business is enabled, as this is a common benign cause for this activity.* Check if the modified credential maps to an existing device ID in Entra ID.* Examine recent activity from the user account, including logon patterns and privilege changes.

Test period:
N/A (single event)
Deduplication:
1 Day
2 variations:
  • Possible shadow credentials addition Medium (parent: Informational)
  • Key credential attribute addition Low (parent: Informational)