Analytics BIOC Informational

User account delegation change

A user account was modified with delegation to a service.

Module:
Identity Analytics
Data source:
Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Persistence (TA0003)
ATT&CK techniques: Account Manipulation (T1098)
Attacker's goals:

An attacker may attempt to control an Active Directory environment.

Investigative actions:

Verify this action with the user who performed the change. Check if the account modified is a service account. Follow actions by the user, including TGT and TGS requests. Monitor for anomalous Kerberos activity.

Test period:
N/A (single event)
Deduplication:
1 Day
2 variations:
  • User account delegation to KRBTGT High (parent: Informational) Adds Steal or Forge Kerberos Tickets (T1558)
  • User account delegation to a DC Low (parent: Informational)