Analytics BIOC
Informational
✕
User account delegation change
A user account was modified with delegation to a service.
- Module:
- Identity Analytics
- Data source:
- Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Persistence (TA0003)
ATT&CK techniques: Account Manipulation (T1098)
Attacker's goals:
An attacker may attempt to control an Active Directory environment.
Investigative actions:
Verify this action with the user who performed the change. Check if the account modified is a service account. Follow actions by the user, including TGT and TGS requests. Monitor for anomalous Kerberos activity.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
2 variations:
- User account delegation to KRBTGT High (parent: Informational) Adds Steal or Forge Kerberos Tickets (T1558)
- User account delegation to a DC Low (parent: Informational)