AN1621
Analytic 1621
Windows
Detects enabling of reversible password encryption in Active Directory or Group Policy, suspicious PowerShell commands modifying AD user properties, and unusual account configuration changes correlated with policy modifications. Multi-event correlation links Group Policy edits, PowerShell command execution, and user account property changes to identify tampering with authentication encryption settings.
WinEventLog:Security
EventCode=4739
WinEventLog:Sysmon
EventCode=1
WinEventLog:PowerShell
EventCode=4103, 4104, 4105, 4106
[MonitoredOUs]
Scope of Organizational Units where reversible encryption property monitoring is enabled.
[TimeWindow]
Time window in which to correlate Group Policy modification and subsequent user property changes.
[SuspiciousCmdletList]
List of PowerShell cmdlets to monitor for account configuration changes.