CTD-000060

AD computer with suspicious change of sAMAccountName

Critical
Active Directory
Credential Access Privilege Escalation
v29

Signature Identity

CTD-000060
Threat ID
29
Version
IOC
Indicator Type

Threat Description

The Common Vulnerabilities and Exposures (CVEs) CVE-2021-42278 and CVE-2021-42287 are security flaws that can be exploited by a threat actor who has obtained access to low-privileged domain user credentials. These vulnerabilities enable the attacker to obtain a Kerberos Service Ticket for a Domain Controller computer account, which provides elevated privileges within a domain.

This escalation of privileges enables the attacker to take control of the domain controller, thereby compromising the security of the entire domain. The domain controller is a critical component of a Windows domain-based network and has a crucial role in managing and enforcing security policies, as well as controlling access to network resources.

Therefore, exploitation of these vulnerabilities can have serious consequences for organizations that are running vulnerable systems, including data breaches, unauthorized access to sensitive information, and the spread of malware. It is highly recommended that organizations apply the necessary patches and updates to protect their systems against these vulnerabilities.

MITRE ATT&CK: Attack Tactics

Credential Access Privilege Escalation

D3FEND: Defend Tactics

Domain Account Monitoring

Remediation

To undo changes using Cayosoft Guardian:

  1. Go to Change History.
  2. Find an unwanted change and select it.
  3. Press Rollback button.

Investigate activities of the user who changed the attribute using Change History.

Frequently Asked Questions

What does AD computer with suspicious change of sAMAccountName mean?

A change has been made to the sAMAccountName attribute on an Active Directory computer object. This may indicate unauthorized access or privilege escalation, allowing attackers to impersonate legitimate users and gain elevated privileges within the domain.

A changed sAMAccountName can directly enable privilege escalation, allowing attackers to take control of the domain controller. This compromises the security of the entire domain and enables attackers to persist within the environment.

Attackers can exploit a changed sAMAccountName on an AD computer by impersonating legitimate users, gaining elevated privileges, and compromising domain security. This allows them to take control of the domain controller, spread malware, access sensitive information, and maintain persistence within the environment.

Cayosoft Guardian continuously monitors changes made to Active Directory objects, including the sAMAccountName attribute. When a suspicious change is detected, Guardian flags it as a security issue and provides administrators with clear visibility into potential threats.

Cayosoft Guardian alerts administrators to changes made to Active Directory objects, enabling them to investigate and roll back unwanted modifications. This proactive approach limits the blast radius of potential attacks and supports ongoing domain account monitoring.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Active Directory
Themes
Account protection
Attack Tactics
Credential Access Privilege Escalation
Defend Tactics
Domain Account Monitoring
Indicator Types
IOC
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical