Windows Security: AD user backdoor via delegation attributes (4738/5136)

Alerts on AD delegation-related attribute changes that may create credentialless account control paths.

FreeUnreviewedSigmahighv1
title: "Windows Security: AD user backdoor via delegation attributes (4738/5136)"
id: b011c347-ef4e-4ef3-8615-5e650ec843ad
status: test
description: This rule flags Active Directory account modifications that can enable an attacker to control other users or computers without possessing their credentials. It matches Windows Security event 4738 (user account change) and LDAP directory change events 5136 involving delegation-relevant attributes such as msDS-AllowedToDelegateTo, servicePrincipalName, and msDS-AllowedToActOnBehalfOfOtherIdentity, excluding empty or null AllowedToDelegateTo values. The detection relies on Security log telemetry for account management changes and directory service change records with attribute-level details.
references:
  - https://msdn.microsoft.com/en-us/library/cc220234.aspx
  - https://adsecurity.org/?p=3466
  - https://blog.harmj0y.net/redteaming/another-word-on-delegation/
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/builtin/security/win_security_alert_ad_user_backdoors.yml
author: "@neu5ron, Huntrule Team"
date: 2017-04-13
modified: 2024-02-26
tags:
  - attack.privilege-escalation
  - attack.t1098
  - attack.persistence
logsource:
  product: windows
  service: security
  definition: "Requirements: Audit Policy : Account Management > Audit User Account Management, Group Policy : Computer Configuration\\Windows Settings\\Security Settings\\Advanced Audit Policy Configuration\\Audit Policies\\Account Management\\Audit User Account Management, DS Access > Audit Directory Service Changes, Group Policy : Computer Configuration\\Windows Settings\\Security Settings\\Advanced Audit Policy Configuration\\Audit Policies\\DS Access\\Audit Directory Service Changes"
detection:
  selection1:
    EventID: 4738
  filter_empty:
    AllowedToDelegateTo:
      - ""
      - "-"
  filter_null:
    AllowedToDelegateTo: null
  selection_5136_1:
    EventID: 5136
    AttributeLDAPDisplayName: msDS-AllowedToDelegateTo
  selection_5136_2:
    EventID: 5136
    ObjectClass: user
    AttributeLDAPDisplayName: servicePrincipalName
  selection_5136_3:
    EventID: 5136
    AttributeLDAPDisplayName: msDS-AllowedToActOnBehalfOfOtherIdentity
  condition: (selection1 and not 1 of filter_*) or 1 of selection_5136_*
falsepositives:
  - Unknown
level: high
license: DRL-1.1
related:
  - id: 300bac00-e041-4ee2-9c36-e262656a6ecc
    type: derived

What it detects

This rule flags Active Directory account modifications that can enable an attacker to control other users or computers without possessing their credentials. It matches Windows Security event 4738 (user account change) and LDAP directory change events 5136 involving delegation-relevant attributes such as msDS-AllowedToDelegateTo, servicePrincipalName, and msDS-AllowedToActOnBehalfOfOtherIdentity, excluding empty or null AllowedToDelegateTo values. The detection relies on Security log telemetry for account management changes and directory service change records with attribute-level details.

Known false positives

  • Unknown

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.