User set insecure CA registry setting for global SANs
A user enabled the EDITF_ATTRIBUTESUBJECTALTNAME2 registry flag, allowing custom Subject Alternative Names (SANs) to be specified on all certificate templates. This could enable attackers to bypass security controls by requesting certificates with user-defined SANs.
- Module:
- Identity Analytics
- Data source:
- XDR Agent with eXtended Threat Hunting (XTH)
This flag can allow an attacker to obtain a certificate with higher privileges and escalate to Domain Admin.
Confirm whether the registry change was authorized by the user or system administrator. Monitor certificate enrollments with Subject Alternate Names. Restore the secure configuration by disabling the EDITF_ATTRIBUTESUBJECTALTNAME2 flag and enforcing strict certificate policies. Investigate any unusual authentication attempts or certificates issued to high-privilege users or accounts.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day