Unusual access to the AD Sync credential files
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent with eXtended Threat Hunting (XTH)
Detection Modules
Cloud
ATT&CK Tactic
Credential Access (TA0006)
ATT&CK Technique
Credentials from Password Stores (T1555)
Severity
Informational
Description
The AD Sync credential files were accessed in an unusual way.
Attacker's Goals
Extracting and decrypting stored Azure AD and Active Directory credentials from Azure AD Connect servers.
Investigative actions
See whether this was a legitimate action.
Follow the causality chain/user/host activities.
Follow unusual actions of the AD Sync user.
Check for remote SMB connections to the agent.
Check for unusual Azure AD authentications.
Check if this happened on other endpoints.
Check for unusual logins.
Variations
Was this helpful?
