Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0589 — Detect Modification of Authentication Process via Reversible Encryption
DET0589

Detect Modification of Authentication Process via Reversible Encryption

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN1621 Analytic 1621
Windows

Detects enabling of reversible password encryption in Active Directory or Group Policy, suspicious PowerShell commands modifying AD user properties, and unusual account configuration changes correlated with policy modifications. Multi-event correlation links Group Policy edits, PowerShell command execution, and user account property changes to identify tampering with authentication encryption settings.

WinEventLog:Security EventCode=4739 WinEventLog:Sysmon EventCode=1 WinEventLog:PowerShell EventCode=4103, 4104, 4105, 4106
[MonitoredOUs] Scope of Organizational Units where reversible encryption property monitoring is enabled.
[TimeWindow] Time window in which to correlate Group Policy modification and subsequent user property changes.
[SuspiciousCmdletList] List of PowerShell cmdlets to monitor for account configuration changes.

Detected Techniques

1

Defense Impairment (1)

Details

MITRE ID
DET0589
STIX ID
x-mitre-detection-strategy--b865c4e8-f3de-471e-846c-2290b6d52da9
Analytics
1
Techniques Detected
1
By Tactic
Defense Impairment
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.