Analytics BIOC
Low
✕
Suspicious account attribute modification that matches that of another account
Suspicious account attribute modification that matches that of another account.
- Module:
- Identity Analytics
- Data source:
- Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Privilege Escalation (TA0004) Persistence (TA0003)
ATT&CK techniques: Account Manipulation (T1098) Valid Accounts: Domain Accounts (T1078.002)
Detector tags: Active Directory Certificate Services Analytics
Attacker's goals:
An attacker might modify account attributes to elevate privileges and get access to strong accounts in the domain.
Investigative actions:
Check if any associated certificates were granted. Check if any login attempts were made by the impersonated accounts using certificates. Check if any Kerberos TGT tickets were generated by the impersonated accounts using certificates.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
1 variation:
- Suspicious account attribute modification that matches that of a sensitive machine account Medium (parent: Low)