Enabled User Right in AD to Control User Objects

 Original Source: [Sigma source]
Title: Enabled User Right in AD to Control User Objects
Status: test
Description:Detects scenario where if a user is assigned the SeEnableDelegationPrivilege right in Active Directory it would allow control of other AD user objects.
References:
  -https://blog.harmj0y.net/activedirectory/the-most-dangerous-user-right-you-probably-have-never-heard-of/
Author: @neu5ron
Date: 2017-07-30
modified:2021-12-02
Tags:
  • -'attack.privilege-escalation'
  • -'attack.persistence'
  • -'attack.t1098'
Logsource:
  • product: windows
  • service: security
  • definition: Requirements: Audit Policy : Policy Change > Audit Authorization Policy Change, Group Policy : Computer Configuration\Windows Settings\Security Settings\Advanced Audit Policy Configuration\Audit Policies\Policy Change\Audit Authorization Policy Change
Detection:
  selection_base:
    EventID: '4704'
  selection_keywords:
    PrivilegeList|contains: 'SeEnableDelegationPrivilege'
  condition:all of selection*
Falsepositives:
  -Unknown
Level: high