Unusual Azure AD sync module load
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent
Detection Modules
Identity Threat Module
ATT&CK Tactic
Credential Access (TA0006)
ATT&CK Technique
OS Credential Dumping (T1003)
Severity
Low
Description
A process that does not usually load the Azure AD Sync mcrypt.dll loaded the module.
Attacker's Goals
Attackers can abuse the Azure AD Connect database files to get access to the AD Sync account.
The AD Sync account is a highly privileged account that can perform a DCSync and get access to on-premise password hashes.
Investigative actions
See whether this was a legitimate action.
Follow process/user/host activities.
Follow unusual actions of the AD Sync user.
Check for unusual Azure AD authentications.
Check for a possible DCSync.
Variations
Was this helpful?
