Windows Security Event 5136: msDS-KeyCredentialLink Shadow Credential Added to AD Object

Alerts on AD attribute changes adding to msDS-KeyCredentialLink via Windows Security EventID 5136, consistent with shadow credential additions.

FreeReviewedSigma · High · v2
Product
windows
Service
security
Author
Nasreddine Bencherchali (Nextron Systems), Elastic (idea) (SigmaHQ), DRL 1.1
Published
2022-10-17
Updated
2026-07-31

ATT&CK techniques

Persistence → Cred Access
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Priv Esc

  6. Discovery

  7. Lateral Movement

  8. Collection

  9. C2

  10. Exfiltration

  11. Impact

What it detects

This rule flags Windows Security audit events where the msDS-KeyCredentialLink attribute is modified, indicating a likely addition of shadow credentials to an Active Directory object. Such changes can enable persistence and credential access by introducing attacker-controlled key credentials. It relies on telemetry from Windows Security logs, specifically Event ID 5136 with the AttributeLDAPDisplayName set to msDS-KeyCredentialLink.

Related detections9 linkedT1556 — drag to rearrange
Suspicious XZ Utils Backdoor Kill-Switch Environment String via process_creation
Suspicious AWS SAML Identity Provider Creation
Suspicious Okta Sign-On Policy Lifecycle Modification
Possible Shadow Credentials Abuse via msDS-KeyCredentialLink Modification
Windows Registry Tampering: DsrmAdminLogonBehavior Value Changes (DSRM)
Azure AD Audit: Trusted Root CA Added for Passwordless Certificate Authentication
Azure AD Audit Logs: Certificate-based authentication enabled via AuthenticationMethodsPolicy update
AWS CloudTrail: AWS Identity Center Identity Provider Configuration Changes
GitHub Audit: High-Risk Security Controls Disabled
Windows Security Event 5136: msDS-KeyCredentialLink Shadow Credential Added to AD Object
Pivot detection · T1556 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.