Analytics BIOC
Low
✕
Unusual CertLog Remote File Write
A remote host wrote to a certificate log file via RPC over SMB, which may indicate the use of an AD CS attack tool like Certipy. This behavior is commonly associated with certificate-based authentication attacks.
- Module:
- Identity Analytics
- Data source:
- XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Credential Access (TA0006)
ATT&CK techniques: Steal or Forge Authentication Certificates (T1649)
Detector tags: Active Directory Certificate Services Analytics
Attacker's goals:
An attacker may be attempting to exploit AD CS misconfigurations and obtain forged authentication certificates for privilege escalation or persistence.
Investigative actions:
Determine whether this was a legitimate certificate request or an unauthorized write operation. Review logs for preceding and subsequent authentication attempts. Investigate the remote host for any suspicious activity. Identify any subsequent Kerberos ticket usage, such as forging or relaying attacks.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
1 variation:
- Suspicious CertLog Remote File Write Medium (parent: Low)