CTD-000046

AD computer using dNSHostName that belongs to another computer account

Critical
Active Directory
Credential Access Privilege Escalation
v74

Signature Identity

CTD-000046
Threat ID
74
Version
IOC
Indicator Type

Threat Description

A threat actor might change dNSHostName of a computer account to the value of the attribute of another computer account. Then the treat actor might obtain a certificate that allows impersonating the target computer account and escalate his privileges.

MITRE ATT&CK: Attack Tactics

Credential Access Privilege Escalation

D3FEND: Defend Tactics

Domain Account Monitoring

Remediation

  1. Investigate suspicious activity of the compromised account using Change History in Cayosoft Guardian.
  2. To protect your environment, complete the following steps for certificate-based authentication:
    1. Update all servers that run Active Directory Certificate Services and Windows domain controllers that service certificate-based authentication with the May 10, 2022 update (see Compatibility mode). The May 10, 2022 update will provide audit events that identify certificates that are not compatible with Full Enforcement mode.
    2. If no audit event logs are created on domain controllers for one month after installing the update, proceed with enabling Full Enforcement mode on all domain controllers. By November 14, 2023, or later, all devices will be updated to Full Enforcement mode. In this mode, if a certificate fails the strong (secure) mapping criteria (see Certificate mappings), authentication will be denied.

Frequently Asked Questions

What does AD computer using dNSHostName that belongs to another computer account mean?

A threat actor changes the dNSHostName attribute of a computer account in Active Directory to match the attribute value of another computer account. This modification enables the attacker to obtain a certificate for impersonating the target computer account.

This threat is rated critical because it allows an attacker to obtain a certificate for impersonating a target computer account, leading to privilege escalation and significant operational impact due to the abuse of certificate-based authentication mechanisms. The modified dNSHostName attribute provides attackers with a valid certificate, enabling them to bypass authentication controls.

Attackers use this vulnerability to impersonate an Active Directory computer account, obtain a certificate for the target account, and escalate privileges by exploiting the modified dNSHostName attribute and associated certificate-based authentication. This allows them to access sensitive resources and data without proper authorization.

Cayosoft Guardian detects this threat by continuously monitoring Active Directory for changes to computer accounts' dNSHostName attributes and identifying potential matches with other accounts' attribute values, enabling real-time detection and alerting.

Cayosoft Guardian helps reduce this risk by providing real-time monitoring and alerting for suspicious activity, offering visibility into certificate-based authentication, and enabling teams to investigate and remediate the issue before privilege escalation occurs. This supports investigation and response efforts by providing detailed information on affected accounts and certificates.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Active Directory
Themes
Account protection
Attack Tactics
Credential Access Privilege Escalation
Defend Tactics
Domain Account Monitoring
Indicator Types
IOC
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical