CTD-000065

AD domain with bulk changes of users

Medium
Active Directory
Impact
v10

Signature Identity

CTD-000065
Threat ID
10
Version
IOC
Indicator Type

Threat Description

Bulk changes might be a result of threat activities. Also, it could be a mistake. Deletions or modifications of AD objects can lead to service outages.

NOTE: This threat rule includes a built-in lookback parameter set to 25 hours. Only events that occurred within this timeframe are processed by the rule.

MITRE ATT&CK: Attack Tactics

Impact

D3FEND: Defend Tactics

User Account Permissions

Remediation

To rollback unwanted changes:
  1. Go to Change History.
  2. Select unwanted changes.
  3. Roll them back.

Frequently Asked Questions

What does AD domain with bulk changes of users mean?

AD domain with bulk changes of users refers to multiple simultaneous modifications made to user accounts within the Active Directory environment domain. This can be a sign of unauthorized access, administrative errors, or both.

AD domain with bulk changes of users is rated medium severity because such changes indicate potential unauthorized access and lateral movement capabilities for attackers. However, deletions or modifications can still lead to service outages and disruptions.

Attackers may use bulk changes to user accounts for privilege escalation by creating a blast radius within the Active Directory environment. This also indicates potential persistence, lateral movement, and unauthorized access within the environment.

Cayosoft Guardian continuously monitors Active Directory for multiple simultaneous changes to user accounts, providing visibility into security issues when detected, allowing administrators to investigate and take corrective action.

Cayosoft Guardian reduces the risk by alerting administrators to investigate and roll back unwanted changes, containing malicious activity and minimizing service outages through its monitoring capabilities.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Active Directory
Themes
Account protection
Attack Tactics
Impact
Defend Tactics
User Account Permissions
Indicator Types
IOC
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical