Windows Security: AD user backdoor via delegation attributes (4738/5136)
Alerts on AD delegation-related attribute changes that may create credentialless account control paths.
FreeUnreviewedSigmahighv1
windows-security-ad-user-backdoor-via-delegation-attributes-4738-5136-300bac00
title: "Windows Security: AD user backdoor via delegation attributes (4738/5136)"
id: b011c347-ef4e-4ef3-8615-5e650ec843ad
status: test
description: This rule flags Active Directory account modifications that can enable an attacker to control other users or computers without possessing their credentials. It matches Windows Security event 4738 (user account change) and LDAP directory change events 5136 involving delegation-relevant attributes such as msDS-AllowedToDelegateTo, servicePrincipalName, and msDS-AllowedToActOnBehalfOfOtherIdentity, excluding empty or null AllowedToDelegateTo values. The detection relies on Security log telemetry for account management changes and directory service change records with attribute-level details.
references:
- https://msdn.microsoft.com/en-us/library/cc220234.aspx
- https://adsecurity.org/?p=3466
- https://blog.harmj0y.net/redteaming/another-word-on-delegation/
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/builtin/security/win_security_alert_ad_user_backdoors.yml
author: "@neu5ron, Huntrule Team"
date: 2017-04-13
modified: 2024-02-26
tags:
- attack.privilege-escalation
- attack.t1098
- attack.persistence
logsource:
product: windows
service: security
definition: "Requirements: Audit Policy : Account Management > Audit User Account Management, Group Policy : Computer Configuration\\Windows Settings\\Security Settings\\Advanced Audit Policy Configuration\\Audit Policies\\Account Management\\Audit User Account Management, DS Access > Audit Directory Service Changes, Group Policy : Computer Configuration\\Windows Settings\\Security Settings\\Advanced Audit Policy Configuration\\Audit Policies\\DS Access\\Audit Directory Service Changes"
detection:
selection1:
EventID: 4738
filter_empty:
AllowedToDelegateTo:
- ""
- "-"
filter_null:
AllowedToDelegateTo: null
selection_5136_1:
EventID: 5136
AttributeLDAPDisplayName: msDS-AllowedToDelegateTo
selection_5136_2:
EventID: 5136
ObjectClass: user
AttributeLDAPDisplayName: servicePrincipalName
selection_5136_3:
EventID: 5136
AttributeLDAPDisplayName: msDS-AllowedToActOnBehalfOfOtherIdentity
condition: (selection1 and not 1 of filter_*) or 1 of selection_5136_*
falsepositives:
- Unknown
level: high
license: DRL-1.1
related:
- id: 300bac00-e041-4ee2-9c36-e262656a6ecc
type: derived
What it detects
This rule flags Active Directory account modifications that can enable an attacker to control other users or computers without possessing their credentials. It matches Windows Security event 4738 (user account change) and LDAP directory change events 5136 involving delegation-relevant attributes such as msDS-AllowedToDelegateTo, servicePrincipalName, and msDS-AllowedToActOnBehalfOfOtherIdentity, excluding empty or null AllowedToDelegateTo values. The detection relies on Security log telemetry for account management changes and directory service change records with attribute-level details.
Known false positives
- Unknown
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.