CTD-000123

AD object with modified msDS-KeyCredentialLink

High
Active Directory
Credential Access Defense Evasion
v14

Signature Identity

CTD-000123
Threat ID
14
Version
IOC
Indicator Type

Threat Description

The Kerberos protocol uses tickets and pre-authentication to grant access. Pre-authentication can be symmetrical (DES, RC4, AES128, AES256) or asymmetrical (PKINIT). PKINIT requires a public-private key pair, with the client encrypting pre-auth data with their private key and the KDC decrypting it with the public key. In Active Directory, a kcl attribute (msDS-KeyCredentialLink) stores raw public keys. If an attacker has control over an account that can edit the kcl, they can gain persistent access to a target user or computer by creating a key pair and appending the public key to the attribute.

MITRE ATT&CK: Attack Tactics

Credential Access Defense Evasion

D3FEND: Defend Tactics

Domain Account Monitoring

Remediation

To undo changes using Cayosoft Guardian:

  1. Go to Change History.
  2. Find an unwanted change and select it.
  3. Press Rollback button.

Investigate activities of the user who changed the attribute using Change History.

Frequently Asked Questions

What does AD object with modified msDS-KeyCredentialLink mean?

An Active Directory account has had its kcl attribute (msDS-KeyCredentialLink) altered, allowing an attacker to append a public key. This change enables attackers to create a key pair and encrypt pre-authentication data using the client's private key.

This modification directly enables persistent access to a target user or computer, allowing attackers to bypass normal authentication controls by creating a key pair and encrypting pre-authentication data using the client's private key.

Attackers can use this persistent access to launch further attacks, such as encrypting pre-authentication data using the client's private key and decrypting it on the KDC side, effectively bypassing normal authentication controls.

Cayosoft Guardian continuously monitors changes to the kcl attribute across Active Directory and flags modifications as security issues for administrators to investigate and take corrective action, providing visibility into potential attack paths.

Cayosoft Guardian provides alerts when unwanted changes occur, allowing administrators to undo them using Change History and limit the attacker's ability to create persistent access points.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Active Directory
Themes
Account protection
Attack Tactics
Credential Access Defense Evasion
Defend Tactics
Domain Account Monitoring
Indicator Types
IOC
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical