logo

Red team sneakiness: Splunking for AD certificate abuse

ID: ed982a74-f928-5654-9886-e921f4c970d7

STIX ID: report--ed982a74-f928-5654-9886-e921f4c970d7

Feed Name: Expel Blog

Threat Score
50/100

Date Published: 2023-09-13

Date Updated: 2026-04-27

Author: Brady Stouffer

...
...

This report describes a red-team abuse of Active Directory Certificate Services (AD CS) and the authors' process for hunting related Windows System EventCode 39 events; they developed two high-fidelity Splunk detections that (1) flag mismatches between the certificate CN and the AccountName and (2) flag CNs that appear to be machine names ending with $. The write-up explains CN extraction from the Subject field, provides example Splunk queries, and recommends scoping and tuning before deployment.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.