Analytics BIOC Informational

Suspicious certificate template modification

A certificate template was updated with a possible misconfiguration. This may indicate the exploitation of misconfigured certificate template access control (ESC4).

Module:
Identity Analytics
Data source:
Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Credential Access (TA0006)
ATT&CK techniques: Steal or Forge Authentication Certificates (T1649)
Detector tags: Active Directory Certificate Services Analytics
Attacker's goals:

An attacker is attempting to exploit AD CS misconfigurations to obtain certificates that can be used for credential theft and privilege escalation.

Investigative actions:

Review the AD CS configuration for vulnerable templates and EKU settings.* Review AD CS logs to identify any unauthorized certificate issuances, modifications, or template changes.

Test period:
N/A (single event)
Deduplication:
1 Hour
2 variations:
  • Certificate template was updated to be vulnerable to AD CS ESC attack Medium (parent: Informational)
  • Certificate template was updated with a misconfiguration configuration Low (parent: Informational)