Sigma Rule Library

Active Directory User Backdoors

Detects scenarios where one can control another users or computers account without having to use their credentials.

View on GitHubOpen raw file

Detection logic

selection1

EventID: 4738

filter_empty

AllowedToDelegateTo:
  - ""
  - "-"

filter_null

AllowedToDelegateTo: null

selection_5136_1

EventID: 5136
AttributeLDAPDisplayName: msDS-AllowedToDelegateTo

selection_5136_2

EventID: 5136
ObjectClass: user
AttributeLDAPDisplayName: servicePrincipalName

selection_5136_3

EventID: 5136
AttributeLDAPDisplayName: msDS-AllowedToActOnBehalfOfOtherIdentity

Condition

(selection1 and not 1 of filter_*) or 1 of selection_5136_*

Raw YAML

title: Active Directory User Backdoors
id: 300bac00-e041-4ee2-9c36-e262656a6ecc
status: test
description: Detects scenarios where one can control another users or computers account without having to use their credentials.
references:
    - https://msdn.microsoft.com/en-us/library/cc220234.aspx
    - https://adsecurity.org/?p=3466
    - https://blog.harmj0y.net/redteaming/another-word-on-delegation/
author: '@neu5ron'
date: 2017-04-13
modified: 2024-02-26
tags:
    - attack.privilege-escalation
    - attack.t1098
    - attack.persistence
logsource:
    product: windows
    service: security
    definition: 'Requirements: Audit Policy : Account Management > Audit User Account Management, Group Policy : Computer Configuration\Windows Settings\Security Settings\Advanced Audit Policy Configuration\Audit Policies\Account Management\Audit User Account Management, DS Access > Audit Directory Service Changes, Group Policy : Computer Configuration\Windows Settings\Security Settings\Advanced Audit Policy Configuration\Audit Policies\DS Access\Audit Directory Service Changes'
detection:
    selection1:
        EventID: 4738
    filter_empty:
        AllowedToDelegateTo:
            - ''
            - '-'
    filter_null:
        AllowedToDelegateTo: null
    selection_5136_1:
        EventID: 5136
        AttributeLDAPDisplayName: 'msDS-AllowedToDelegateTo'
    selection_5136_2:
        EventID: 5136
        ObjectClass: 'user'
        AttributeLDAPDisplayName: 'servicePrincipalName'
    selection_5136_3:
        EventID: 5136
        AttributeLDAPDisplayName: 'msDS-AllowedToActOnBehalfOfOtherIdentity'
    condition: (selection1 and not 1 of filter_*) or 1 of selection_5136_*
falsepositives:
    - Unknown
level: high

False positives

  • Unknown

References

Similar rules