Analytics BIOC
Informational
✕
Suspicious certificate template modification
A certificate template was updated with a possible misconfiguration. This may indicate the exploitation of misconfigured certificate template access control (ESC4).
- Module:
- Identity Analytics
- Data source:
- Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Credential Access (TA0006)
ATT&CK techniques: Steal or Forge Authentication Certificates (T1649)
Detector tags: Active Directory Certificate Services Analytics
Attacker's goals:
An attacker is attempting to exploit AD CS misconfigurations to obtain certificates that can be used for credential theft and privilege escalation.
Investigative actions:
Review the AD CS configuration for vulnerable templates and EKU settings.* Review AD CS logs to identify any unauthorized certificate issuances, modifications, or template changes.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Hour
2 variations:
- Certificate template was updated to be vulnerable to AD CS ESC attack Medium (parent: Informational)
- Certificate template was updated with a misconfiguration configuration Low (parent: Informational)