For the complete documentation index, see llms.txt. This page is also available as Markdown.

User account delegation change

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

Requires one of the following data sources: Windows Event Collector OR XDR Agent with eXtended Threat Hunting (XTH)

Detection Modules

Identity Analytics

ATT&CK Tactic

Persistence (TA0003)

ATT&CK Technique

Account Manipulation (T1098)

Severity

Informational

Description

A user account was modified with delegation to a service.

Attacker's Goals

An attacker may attempt to control an Active Directory environment.

Investigative actions

  • Verify this action with the user who performed the change.

  • Check if the account modified is a service account.

  • Follow actions by the user, including TGT and TGS requests.

  • Monitor for anomalous Kerberos activity.

Variations

User account delegation to KRBTGT

Synopsis

Field
Value

ATT&CK Tactic

Credential Access (TA0006)

ATT&CK Technique

Steal or Forge Kerberos Tickets (T1558)

Severity

High

Description

A user account was modified with delegation to the KRBTGT service.

Attacker's Goals

An attacker may attempt to control an Active Directory environment.

Investigative actions

  • Verify this action with the user who performed the change.

  • Check if the account modified is a service account.

  • Follow actions by the user, including TGT and TGS requests.

  • Monitor for anomalous Kerberos activity.

User account delegation to a DC

Synopsis

Field
Value

ATT&CK Tactic

Persistence (TA0003)

ATT&CK Technique

Account Manipulation (T1098)

Severity

Low

Description

A user account was modified with delegation to a service on a domain controller.

Attacker's Goals

An attacker may attempt to control an Active Directory environment.

Investigative actions

  • Verify this action with the user who performed the change.

  • Check if the account modified is a service account.

  • Follow actions by the user, including TGT and TGS requests.

  • Monitor for anomalous Kerberos activity.

Was this helpful?