Unusual ADConnect database file access
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK Tactic
Credential Access (TA0006)
ATT&CK Technique
Unsecured Credentials (T1552)
Severity
Informational
Description
An unusual process accessed the ADConnect database files.
Attacker's Goals
Attackers can abuse the Azure AD Connect database files to get access to the AD Sync account.
The AD Sync account is a highly privileged account that can perform a DCSync and get access to on-premise password hashes.
Investigative actions
See whether this was a legitimate action.
Follow process/user/host activities.
Follow unusual actions of the AD Sync user.
Check for unusual Azure AD authentications.
Check for a possible DCSync.
Variations
Was this helpful?
