CTD-000148

Insufficient Active Directory domain controller auditing policy configuration

Medium
Active Directory
Defense Evasion
v14

Signature Identity

CTD-000148
Threat ID
14
Version
IOA-IOC-IOE
Indicator Type

Threat Description

This threat checks whether your organization has sufficient auditing settings for your AD domain controllers, which helps organizations alert of suspicious activity that could lead to lateral movement and privilege escalation, including a complete domain compromise.

MITRE ATT&CK: Attack Tactics

Defense Evasion

D3FEND: Defend Tactics

Application Configuration Hardening

Remediation

Ensure the changes outlined in the Evidence are implemented based on the Audit Policy Recommendations article. The following is an example of how to configure one specific audit setting:
E.g., enable auditing for Account Logon by running the following script using PowerShell as an administrator:
auditpol /set /subcategory:"Kerberos Authentication Service" /success:enable /failure:enable

Frequently Asked Questions

What does Insufficient Active Directory domain controller auditing policy configuration mean?

Insufficient Active Directory domain controller auditing policy configuration refers to the absence of proper auditing settings for AD domain controllers, which can conceal malicious activity and hinder incident detection.

This issue is rated medium severity because it allows attackers to move undetected within the environment without granting administrative control. However, the lack of visibility into domain controller activity can facilitate attack planning and execution.

Attackers can leverage this vulnerability to move laterally within the environment, accessing sensitive data or disrupting operations. This is because the lack of visibility into domain controller activity enables them to plan and execute attacks without being detected.

Cayosoft Guardian continuously monitors the auditing settings for your AD domain controllers, identifying missing or inadequate audit policies to provide early detection and alert administrators to the issue.

Cayosoft Guardian helps mitigate this risk by providing visibility into domain controller activity, enabling necessary audit settings such as Account Logon, and supporting investigation and response efforts to minimize attack impact.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Active Directory
Themes
Infrastructure
Attack Tactics
Defense Evasion
Defend Tactics
Application Configuration Hardening
Indicator Types
IOA IOC IOE
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical