For the complete documentation index, see llms.txt. This page is also available as Markdown.

Unusual Azure AD sync module load

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

XDR Agent

Detection Modules

Identity Threat Module

ATT&CK Tactic

Credential Access (TA0006)

ATT&CK Technique

OS Credential Dumping (T1003)

Severity

Low

Description

A process that does not usually load the Azure AD Sync mcrypt.dll loaded the module.

Attacker's Goals

  • Attackers can abuse the Azure AD Connect database files to get access to the AD Sync account.

  • The AD Sync account is a highly privileged account that can perform a DCSync and get access to on-premise password hashes.

Investigative actions

  • See whether this was a legitimate action.

  • Follow process/user/host activities.

  • Follow unusual actions of the AD Sync user.

  • Check for unusual Azure AD authentications.

  • Check for a possible DCSync.

Variations

Unusual Azure AD sync module load by suspicious process

Synopsis

Field
Value

ATT&CK Tactic

Credential Access (TA0006)

ATT&CK Technique

OS Credential Dumping (T1003)

Severity

Medium

Description

A suspicious process that does not usually load the Azure AD Sync mcrypt.dll loaded the module.

Attacker's Goals

  • Attackers can abuse the Azure AD Connect database files to get access to the AD Sync account.

  • The AD Sync account is a highly privileged account that can perform a DCSync and get access to on-premise password hashes.

Investigative actions

  • See whether this was a legitimate action.

  • Follow process/user/host activities.

  • Follow unusual actions of the AD Sync user.

  • Check for unusual Azure AD authentications.

  • Check for a possible DCSync.

Was this helpful?