Analytics BIOC Informational

Unusual access to the AD Sync credential files

The AD Sync credential files were accessed in an unusual way.

Module:
Cortex Cloud
Licensed by:
Cloud Runtime Security (CRS)
Data source:
XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Credential Access (TA0006)
ATT&CK techniques: Credentials from Password Stores (T1555)
Attacker's goals:

Extracting and decrypting stored Azure AD and Active Directory credentials from Azure AD Connect servers.

Investigative actions:

See whether this was a legitimate action. Follow the causality chain/user/host activities. Follow unusual actions of the AD Sync user. Check for remote SMB connections to the agent. Check for unusual Azure AD authentications. Check if this happened on other endpoints. Check for unusual logins.

Test period:
N/A (single event)
Deduplication:
1 Day
2 variations:
  • Suspicious process access to the AD Sync credential files Medium (parent: Informational)
  • An abnormal process accessed the AD Sync credential files Low (parent: Informational)