CTD-000027

Built-in domain Administrator account used recently

Critical
Active Directory
Defense Evasion
v85

Signature Identity

CTD-000027
Threat ID
85
Version
IOC
Indicator Type

Threat Description

The usage of a built-in domain Administrator account might be an indication that the account has been compromised. The built-in domain Administrator account should not be used for day-to-day management tasks.

MITRE ATT&CK: Attack Tactics

Defense Evasion

D3FEND: Defend Tactics

Domain Account Monitoring

Remediation

  1. Use Cayosoft Guardian Change History to find and review changes made by the built-in Domain Administrator account.
  2. Set a complex password for this account.
  3. Ensure that it is not used to perform daily management tasks.

Frequently Asked Questions

What does Built-in domain Administrator account used recently mean?

The built-in domain Administrator account has been accessed or used within a certain timeframe, which may indicate that the account has been compromised. This high-privilege account should not be used for day-to-day management tasks.

The built-in domain Administrator account has high-privilege access to the domain, and its unauthorized use can lead to compromise of identity infrastructure or business-critical systems due to the ability to perform administrative tasks and modify security settings. This creates a significant attack path for attackers to exploit.

An attacker who uses a built-in domain Administrator account gains high-privilege access, allowing them to perform administrative tasks, modify security settings, and potentially escalate privileges further. This can lead to significant operational impact and compromise of sensitive data.

Cayosoft Guardian monitors changes made to the built-in Domain Administrator account, including login activity and password changes, providing visibility into potential unauthorized access to high-privilege credentials.

Cayosoft Guardian alerts administrators to review changes made by the built-in Domain Administrator account using Change History, enabling teams to identify and address potential compromise promptly and reducing the blast radius of a potential attack.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Active Directory
Themes
Account protection
Attack Tactics
Defense Evasion
Defend Tactics
Domain Account Monitoring
Indicator Types
IOC
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical