User set insecure CA registry setting for global SANs
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent with eXtended Threat Hunting (XTH)
Detection Modules
Identity Analytics
Detector Tags
Active Directory Certificate Services Analytics
ATT&CK Tactic
Defense Impairment (TA0112)
ATT&CK Technique
Disable or Modify Tools (T1685)
Severity
Low
Description
A user enabled the EDITF_ATTRIBUTESUBJECTALTNAME2 registry flag, allowing custom Subject Alternative Names (SANs) to be specified on all certificate templates. This could enable attackers to bypass security controls by requesting certificates with user-defined SANs.
Attacker's Goals
This flag can allow an attacker to obtain a certificate with higher privileges and escalate to Domain Admin.
Investigative actions
Confirm whether the registry change was authorized by the user or system administrator.
Monitor certificate enrollments with Subject Alternate Names.
Restore the secure configuration by disabling the EDITF_ATTRIBUTESUBJECTALTNAME2 flag and enforcing strict certificate policies.
Investigate any unusual authentication attempts or certificates issued to high-privilege users or accounts.
Was this helpful?
