Red team sneakiness: Splunking for AD certificate abuse
ID: ed982a74-f928-5654-9886-e921f4c970d7
STIX ID: report--ed982a74-f928-5654-9886-e921f4c970d7
Feed Name: Expel Blog
This report describes a red-team abuse of Active Directory Certificate Services (AD CS) and the authors' process for hunting related Windows System EventCode 39 events; they developed two high-fidelity Splunk detections that (1) flag mismatches between the certificate CN and the AccountName and (2) flag CNs that appear to be machine names ending with $. The write-up explains CN extraction from the Subject field, provides example Splunk queries, and recommends scoping and tuning before deployment.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
