Deletion of AD CS certificate database entries
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
Requires one of the following data sources: Windows Event Collector OR XDR Agent with eXtended Threat Hunting (XTH)
Detection Modules
Identity Analytics
Detector Tags
Active Directory Certificate Services Analytics
ATT&CK Tactic
Defense Evasion (TA0005)
ATT&CK Technique
Indicator Removal (T1070)
Severity
Informational
Description
A user has deleted rows from the certificate database of an AD CS server.
Attacker's Goals
An attacker is attempting to cover their tracks after issuing certificates.
Investigative actions
Check the user account deleting the certificate database entries and verify its activity.* Review AD CS logs to identify any unauthorized certificate issuances, modifications, or template changes.* Examine recent activity from the user account, including logon patterns and privilege changes.
Variations
Was this helpful?
