For the complete documentation index, see llms.txt. This page is also available as Markdown.

Unusual ADConnect database file access

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

XDR Agent with eXtended Threat Hunting (XTH)

ATT&CK Tactic

Credential Access (TA0006)

ATT&CK Technique

Unsecured Credentials (T1552)

Severity

Informational

Description

An unusual process accessed the ADConnect database files.

Attacker's Goals

  • Attackers can abuse the Azure AD Connect database files to get access to the AD Sync account.

  • The AD Sync account is a highly privileged account that can perform a DCSync and get access to on-premise password hashes.

Investigative actions

  • See whether this was a legitimate action.

  • Follow process/user/host activities.

  • Follow unusual actions of the AD Sync user.

  • Check for unusual Azure AD authentications.

  • Check for a possible DCSync.

Variations

Suspicious access to ADConnect database file

Synopsis

Field
Value

ATT&CK Tactic

Credential Access (TA0006)

ATT&CK Technique

Unsecured Credentials (T1552)

Severity

Medium

Description

An unusual process accessed the ADConnect database files with some suspicious characteristics that flagged this access attempt as a suspicious.

Attacker's Goals

  • Attackers can abuse the Azure AD Connect database files to get access to the AD Sync account.

  • The AD Sync account is a highly privileged account that can perform a DCSync and get access to on-premise password hashes.

Investigative actions

  • See whether this was a legitimate action.

  • Follow process/user/host activities.

  • Follow unusual actions of the AD Sync user.

  • Check for unusual Azure AD authentications.

  • Check for a possible DCSync.

Access to ADConnect database file by an unsigned or unusual process

Synopsis

Field
Value

ATT&CK Tactic

Credential Access (TA0006)

ATT&CK Technique

Unsecured Credentials (T1552)

Severity

Low

Description

An unusual process accessed the ADConnect database files with some suspicious characteristics that flagged this access attempt as a suspicious access.

Attacker's Goals

  • Attackers can abuse the Azure AD Connect database files to get access to the AD Sync account.

  • The AD Sync account is a highly privileged account that can perform a DCSync and get access to on-premise password hashes.

Investigative actions

  • See whether this was a legitimate action.

  • Follow process/user/host activities.

  • Follow unusual actions of the AD Sync user.

  • Check for unusual Azure AD authentications.

  • Check for a possible DCSync.

Was this helpful?