Enable Auditing of Changes to msDS-KeyCredentialLink
ID: aeb6c484-fb4b-5012-9547-26ed5f74618f
STIX ID: report--aeb6c484-fb4b-5012-9547-26ed5f74618f
Feed Name: Black Hills Infosec Blog
This post describes how to configure Active Directory auditing for the msDS-KeyCredentialLink attribute (schema GUID 5b47d60f-6090-40b2-9f37-2a4de88f3063) to detect modifications used in privilege escalation, provides PowerShell commands (including Set-AuditRule.ps1) to apply the audit rule across a domain, and supplies a Microsoft Sentinel KQL query to hunt for EventID 5136 changes to that attribute.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
