Attacking smart cards in active directory
ID: d669bb0e-5394-5f8e-b538-64a94aac8087
STIX ID: report--d669bb0e-5394-5f8e-b538-64a94aac8087
Feed Name: SensePost Blog
This report explains a smart card/Active Directory impersonation technique in which an attacker with permissions to change User Principal Names (UPNs) modifies a victim’s UPN to match the Subject Alternative Name (SAN) on the attacker’s legitimate smart card certificate, causing domain controllers to authenticate the attacker as the victim. It outlines prerequisites (delegated UPN-change rights, valid smart card), execution using tools like dsmod, and operational use cases, then recommends monitoring for UPN changes (event ID 4738), minimizing who can change UPNs, and treating UPN/SPN values as sensitive to detect and reduce exposure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
