Windows AD DNS Record Modification Indicators for Kerberos Coercion via SPN DNS Spoofing

Alerts on AD MicrosoftDNS DNS node changes whose DN contains a CREDENTIAL_TARGET_INFORMATION base64 marker tied to Kerberos coercion.

FreeReviewedSigma · High · v2
Product
windows
Service
security
Author
Swachchhanda Shrawan Poudel (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2025-06-20
Updated
2026-07-31

ATT&CK techniques

Cred Access → Collection
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Discovery

  9. Lateral Movement

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule flags Active Directory DNS object changes where the DNS node Distinguished Name contains a base64-encoded marker matching a marshaled CREDENTIAL_TARGET_INFORMATION pattern. Such tampering can support Kerberos coercion by redirecting authentication to attacker-controlled destinations through spoofed SPNs. It relies on Windows Security events for directory service object creation/modification and access (Event IDs 5136, 5137, and 4662) that include the targeted MicrosoftDNS object DN/AdditionalInfo.

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.