CTD-000086

AD forest with recent changes to default security descriptor in schema

Medium
Active Directory
Defense Evasion
v21

Signature Identity

CTD-000086
Threat ID
21
Version
IOC
Indicator Type

Threat Description

Recent changes to the schema attribute of the default security descriptor might be an indication of threat activities. A threat actor with permissions to modify AD schema might alter the defaultSecurityDescriptor attribute on any AD object class. Such a change will affect all newly created objects and might sufficiently decrease the security of your Active Directory forest. As schema changes are irreversible, a forest recovery process is the only solution to undo such changes.

MITRE ATT&CK: Attack Tactics

Defense Evasion

D3FEND: Defend Tactics

Domain Account Monitoring

Remediation

Review changes to the default security descriptor. Such changes are rare, and there should be a reason for every change. Schema changes could weaken the security of your environment.

Frequently Asked Questions

What does AD forest with recent changes to default security descriptor in schema mean?

A modification has been made to the defaultSecurityDescriptor attribute on an AD object class, which affects all newly created objects. This change can decrease the security of the Active Directory environment forest if not properly managed.

The modified defaultSecurityDescriptor attribute does not grant immediate administrative control, but it can weaken the security of the Active Directory environment forest. Schema changes are irreversible and require careful consideration.

A threat actor may have altered the defaultSecurityDescriptor attribute on an AD object class, allowing them to create objects with reduced access controls. This can facilitate further compromise or lateral movement within the Active Directory environment.

Cayosoft Guardian continuously monitors the state of the defaultSecurityDescriptor attribute across Active Directory objects. When a modification is detected, Guardian flags it as a security issue for administrator review and provides visibility into potential threat activities.

Cayosoft Guardian alerts administrators to potential threat activities by detecting unauthorized modifications to the defaultSecurityDescriptor attribute. Guardian also supports ongoing monitoring, ensuring that similar changes are quickly identified and addressed, and assists response efforts by providing a clear audit trail of changes.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Active Directory
Themes
AD Delegation Forest-wide Schema
Attack Tactics
Defense Evasion
Defend Tactics
Domain Account Monitoring
Indicator Types
IOC
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical