A machine certificate was issued with a mismatch
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
Requires one of the following data sources: Windows Event Collector OR XDR Agent with eXtended Threat Hunting (XTH)
Detection Modules
Identity Analytics
Detector Tags
Active Directory Certificate Services Analytics
ATT&CK Tactic
Privilege Escalation (TA0004)
ATT&CK Technique
Valid Accounts: Domain Accounts (T1078.002)
Severity
Medium
Description
A machine certificate was issued with a mismatch between the requester and the subject.
Attacker's Goals
An attacker may attempt to exploit the Active Directory Certificate Services to escalate privileges to a domain controller machine account.
Investigative actions
Check who owns the certificate requester account.
Check if the requester DNS name attribute was changed recently.
Investigate actions done by the requester and its owner.
Check for possible DCSync alerts.
Was this helpful?
