Suspicious Modification of msDS-KeyCredentialLink for Shadow Credential Abuse

PremiumReviewedSigma · High · v1
Product
windows
Service
security
Author
HuntRule
Published
2026-10-01
Updated
2026-10-01

ATT&CK techniques

Persistence → Lateral Movement

What it detects

This rule detects Active Directory directory-service changes writing to the msDS-KeyCredentialLink attribute, the shadow-credential primitive used in the Huntress dMSA Ouroboros technique to obtain PKINIT authentication material on Windows Server 2025. Populating this attribute lets an attacker request Kerberos tickets and extract credentials for the target object. Modification outside device registration or trusted CA workflows is a strong indicator of credential-access abuse.

Related detections9 linkedT1003 — drag to rearrange
Rubeus HackTool Execution via PowerShell ScriptBlock Flags (Windows)
Windows: Uncommon Outbound Kerberos Traffic on Port 88
Windows Process Creation: Rubeus HackTool Execution Indicators
Antivirus Credential Dumping Signature Match (Password Dumpers/Stealers)
Suspicious dMSA Membership Modification via msDS-GroupMSAMembership Attribute
Malicious Kerberos Diamond Ticket Forgery via Rubeus
Possible OxideHarvest Stealer Execution via Combined Short Flag Set
Suspicious Rubeus Kerberos Abuse Tool Execution from Downloads
Suspicious Credential Dump Attempt via Task Manager (via process_creation)
Suspicious Modification of msDS-KeyCredentialLink for Shadow Credential Abuse
Pivot detection · T1003 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.