CTD-000048

AD computer with traces of DCShadow attack

Critical
Active Directory
Collection Credential Access Defense Evasion Privilege Escalation
v45

Signature Identity

CTD-000048
Threat ID
45
Version
IOC
Indicator Type

Threat Description

The computer object with specific values in the servicePrincipalName attribute is an indication of hacker tools used in your environment. The Mimikatz tool creates a shadow domain controller to push malicious changes to the Active Directory and leaves identifiable traces on a computer object that was used in an attack. Changes in the Active Directory made by the Mimikatz tool bypass native security logs and allow a malicious user to stay unnoticed. However, Cayosoft Guardian is able to detect changes made with the Mimikatz tool. You will be able to identify such changes by the missing initiator in the Who column in the Change History.

MITRE ATT&CK: Attack Tactics

Collection Credential Access Defense Evasion Privilege Escalation

D3FEND: Defend Tactics

Domain Account Monitoring

Remediation

  1. Isolate and investigate computers with possible evidence of the Mimikatz tool usage.
  2. Review suspicious changes in the Active Directory made around the time when SPN was added and where the initiator was not detected. 

To remove a Service Principal Name from a computer account in Active Directory using Active Directory Users and Computers, follow these step-by-step instructions:

  1. Open the Active Directory Users and Computers snap-in:
    1. Click the Start button.
    2. Select Administrative Tools.
    3. Select Active Directory Users and Computers.
  2. In the left pane of the console expand the domain.
  3. Expand the Computers container.
  4. Locate the computer account.
  5. Right-click the computer account and select Properties.
  6. In the Properties dialog box, select the Attribute Editor tab.
  7. Scroll down the list of attributes until you find the servicePrincipalName attribute, and then select it.
  8. Click the Edit button.
  9. In the Multi-valued String Editor dialog box, locate the SPN that you want to remove.
  10. Select the SPN.
  11. Click the Remove button.
  12. Click OK to close the Multi-valued String Editor dialog box.
  13. Click OK again to close the Properties dialog box.

Note: Removing a Service Principal Name from the computer does not help you to remediate the issue. Your environment is compromised. Learn more: Planning for Compromise | Microsoft Learn

Frequently Asked Questions

What does AD computer with traces of DCShadow attack mean?

AD computer with traces of DCShadow attack indicates that a computer object in the Active Directory environment has been modified by an attacker using the Mimikatz tool. This tool creates a shadow domain controller to push malicious changes to the Active Directory, which can be identified by specific values in the servicePrincipalName attribute.

The presence of DCShadow attack traces means an attacker has successfully bypassed native security logs and compromised the environment. This allows malicious users to remain undetected, making it a high-severity issue.

Attackers use a compromised computer object in Active Directory as evidence of their successful compromise. This enables them to maintain persistence and continue making malicious changes without detection, potentially leading to unauthorized access and manipulation of security settings.

Cayosoft Guardian detects AD computer with traces of DCShadow attack by monitoring Active Directory for changes made using the Mimikatz tool. When such changes are detected, Guardian flags them as a security issue and provides visibility into the compromised environment.

Cayosoft Guardian helps reduce the risk by alerting administrators to investigate computers with possible evidence of Mimikatz tool usage. This allows teams to isolate and remediate the compromised environment, preventing further malicious activity.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Active Directory
Themes
DCShadow Mimikatz
Attack Tactics
Collection Credential Access Defense Evasion Privilege Escalation
Defend Tactics
Domain Account Monitoring
Indicator Types
IOC
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical