Analytics BIOC Informational

Vulnerable certificate template loaded

A possible misconfigured certificate template was loaded by Certificate Services. This may indicate potential certificate template abuse.

Module:
Identity Analytics
Data source:
Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Credential Access (TA0006)
ATT&CK techniques: Steal or Forge Authentication Certificates (T1649)
Detector tags: Active Directory Certificate Services Analytics
Attacker's goals:

An attacker is attempting to exploit AD CS misconfigurations to obtain certificates that can be used for credential theft and privilege escalation.

Investigative actions:

Review the AD CS configuration for vulnerable templates and EKU settings. Review AD CS logs to identify any unauthorized certificate issuances, modifications, or template changes. Look for signs of certificate template enumeration via LDAP. Inspect certificates issued to privileged accounts. Check for abnormal PKINIT authentication or elevated Kerberos tickets.

Test period:
N/A (single event)
Deduplication:
1 Day
2 variations:
  • First detection of AD CS ESC vulnerability in certificate template Medium (parent: Informational)
  • Certificate template vulnerable to AD CS ESC attack Low (parent: Informational)