Suspicious Certutil AD CS contact
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent
Detector Tags
Active Directory Certificate Services Analytics
ATT&CK Tactic
Discovery (TA0007), Credential Access (TA0006)
ATT&CK Technique
System Service Discovery (T1007), Steal or Forge Authentication Certificates (T1649)
Severity
Low
Description
A suspicious occurrence of Certutil attempted to contact the AD CS Request Interface.
Attacker's Goals
An attacker might look for AD CS servers, certificate templates or request certificates.
With the wrong setting or loose vulnerable templates or enabled enrollment, the attacker will be able to authenticate as users on the network.
Investigative actions
Look at further action done by the user.
Investigate whether other non-standard operations were done regarding the AD CS.
Variations
Was this helpful?
