CTD-000199

AD account configured or modified to use RC4 encryption

High
Active Directory
Credential Access Defense Evasion Lateral Movement
v7

Signature Identity

CTD-000199
Threat ID
7
Version
IOA-IOE
Indicator Type

Threat Description

This threat identifies Active Directory security principals, such as users, computer objects, and service accounts, that either currently have RC4-HMAC enabled (indicator of exposure) or were recently modified to enable RC4-HMAC through changes to the msDS-SupportedEncryptionTypes attribute (indicator of attack).

RC4 is deprecated, cryptographically weak, and commonly associated with attacks such as password cracking, Kerberoasting, and forged Kerberos tickets. Enabling RC4-HMAC may indicate an encryption downgrade attempt in which an adversary weakens Kerberos protections to obtain service tickets that are easier to crack.

MITRE ATT&CK: Attack Tactics

Credential Access Defense Evasion Lateral Movement

D3FEND: Defend Tactics

Credential Hardening

Remediation

RC4 is deprecated, cryptographically weak, and commonly associated with attacks such as password cracking, Kerberoasting, and forged Kerberos tickets. Enabling RC4-HMAC may indicate an encryption downgrade attempt in which an adversary weakens Kerberos protections to obtain service tickets that are easier to crack.

Remediation:
  1. Confirm that no application, service, or legacy dependency still requires RC4.
  2. Engage the relevant system owners, because RC4 should be removed consistently across all affected environments.
  3. Remove RC4 from the account’s supported Kerberos encryption types by clearing the RC4 flag (0x4) in the msDS-SupportedEncryptionTypes attribute.
  4. Configure the account to use AES encryption only. Recommended value: 24 (AES128 + AES256).
  5. Reset the account password or rotate the service account secret to invalidate previously issued tickets and reduce the risk of ticket reuse.
  6. If this alert reflects a recent change, review Cayosoft Guardian Change History and related audit events to determine who made the change and whether it was authorized.
  7. Investigate for additional suspicious activity, including unauthorized changes to other sensitive account attributes or related Kerberos settings.

Frequently Asked Questions

What does AD account configured or modified to use RC4 encryption mean?

An Active Directory security principal has been configured to use the RC4 encryption protocol, which can be due to an encryption downgrade attempt by an attacker.

Enabling RC4-HMAC directly weakens Kerberos protections, allowing attackers to obtain service tickets that are easier to crack. This can lead to serious security breaches and data compromise due to the ability of attackers to exploit the weak protocol.

Attackers can exploit the weak RC4 protocol to crack passwords, obtain forged Kerberos tickets, and gain unauthorized access to sensitive resources. This enables lateral movement within the domain and increases the risk of data breach.

Cayosoft Guardian continuously monitors Active Directory security principals for the presence of RC4-HMAC, flagging affected accounts as security issues so administrators can take corrective action.

Cayosoft Guardian alerts administrators when it detects RC4-HMAC, enabling them to remove it from affected accounts' supported Kerberos encryption types. This limits attackers' ability to exploit weak encryption and reduces the risk of compromise.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Active Directory
Themes
Account protection Forest-wide Privileged Access Management
Attack Tactics
Credential Access Defense Evasion Lateral Movement
Defend Tactics
Credential Hardening
Indicator Types
IOA IOE
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical