CTD-000066

AD domain with bulk changes of groups

Medium
Active Directory
Impact
v10

Signature Identity

CTD-000066
Threat ID
10
Version
IOC
Indicator Type

Threat Description

Bulk changes might be a result of threat activities. Also, it could be a mistake. Deletions or modifications of AD objects can lead to service outages.

NOTE: This threat rule includes a built-in lookback parameter set to 25 hours. Only events that occurred within this timeframe are processed by the rule.

MITRE ATT&CK: Attack Tactics

Impact

D3FEND: Defend Tactics

User Account Permissions

Remediation

To rollback unwanted changes:
  1. Go to Change History.
  2. Select unwanted changes.
  3. Roll them back.

Frequently Asked Questions

What does AD domain with bulk changes of groups mean?

AD domain with bulk changes of groups refers to multiple simultaneous modifications or deletions of Active Directory objects, such as user accounts, group memberships, or organizational units. This can be a sign of unauthorized access or an administrative error.

These changes can cause service disruptions and potentially grant attackers access to affected objects, making it a moderate risk scenario.

Attackers may modify group memberships to gain unauthorized access to sensitive resources. Alternatively, they might attempt to evade detection by making multiple small changes rather than a single large modification, exploiting the lack of auditing and monitoring.

Cayosoft Guardian detects AD domain with bulk changes of groups by continuously monitoring Active Directory for simultaneous modifications or deletions of objects. When such changes are detected, Guardian flags them as a security issue so administrators can investigate and take corrective action.

Cayosoft Guardian provides visibility into these changes, allowing administrators to quickly identify and roll back unwanted modifications. This limits potential attacker access and prevents service disruptions.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Active Directory
Themes
Account protection
Attack Tactics
Impact
Defend Tactics
User Account Permissions
Indicator Types
IOC
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical