For the complete documentation index, see llms.txt. This page is also available as Markdown.

The CA policy EditFlags was queried

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

XDR Agent

Detector Tags

Active Directory Certificate Services Analytics

ATT&CK Tactic

Privilege Escalation (TA0004)

ATT&CK Technique

Valid Accounts (T1078)

Severity

Medium

Description

The CA policy EditFlags was queried.

Attacker's Goals

  • Querying this registry value can indicate an attacker is looking for an enabled EDITF_ATTRIBUTESUBJECTALTNAME2 flag.

  • When this flag is enabled, it allows users to request certificates with a Subject Alternate Name(SAN).

  • This can allow an attacker to obtain a certificate with higher privileges.

Investigative actions

  • Check if the action was allowed by the user.

  • Monitor certificate enrollments with Subject Alternate Names.

  • Check for unusual high privilege users certificate authentications.

Was this helpful?