Active Directory User Backdoors

 Original Source: [Sigma source]
Title: Active Directory User Backdoors
Status: test
Description:Detects scenarios where one can control another users or computers account without having to use their credentials.
References:
  -https://msdn.microsoft.com/en-us/library/cc220234.aspx
  -https://adsecurity.org/?p=3466
  -https://blog.harmj0y.net/redteaming/another-word-on-delegation/
Author: @neu5ron
Date: 2017-04-13
modified:2024-02-26
Tags:
  • -'attack.privilege-escalation'
  • -'attack.t1098'
  • -'attack.persistence'
Logsource:
  • product: windows
  • service: security
  • definition: Requirements: Audit Policy : Account Management > Audit User Account Management, Group Policy : Computer Configuration\Windows Settings\Security Settings\Advanced Audit Policy Configuration\Audit Policies\Account Management\Audit User Account Management, DS Access > Audit Directory Service Changes, Group Policy : Computer Configuration\Windows Settings\Security Settings\Advanced Audit Policy Configuration\Audit Policies\DS Access\Audit Directory Service Changes
Detection:
  selection1:
    EventID: '4738'
  filter_empty:
    AllowedToDelegateTo:
      -''
      -'-'

  filter_null:
    AllowedToDelegateTo: 'None'
  selection_5136_1:
    EventID: '5136'
    AttributeLDAPDisplayName: 'msDS-AllowedToDelegateTo'
  selection_5136_2:
    EventID: '5136'
    ObjectClass: 'user'
    AttributeLDAPDisplayName: 'servicePrincipalName'
  selection_5136_3:
    EventID: '5136'
    AttributeLDAPDisplayName: 'msDS-AllowedToActOnBehalfOfOtherIdentity'
  condition:(selection1 and not 1 of filter_*) or 1 of selection_5136_*
Falsepositives:
  -Unknown
Level: high