Detection: Windows AD Computer SPN Modified By User Account

Description

The following analytic detects a user account (non-machine account) adding or removing a servicePrincipalName (SPN) on a computer object in Active Directory, via Windows Security Event 5136. In normal AD operations, SPN values on computer objects are managed exclusively by the computer account itself (during domain join or name change), by Domain Controllers during replication, or by the SYSTEM/NETWORK SERVICE context — all of which appear as accounts ending in the dollar sign ($) convention. A named user account writing to the servicePrincipalName attribute of a computer object is anomalous and may indicate an attacker with delegated WriteProperty rights over computer accounts performing SPN manipulation.

 1`wineventlog_security`
 2EventCode=5136
 3AttributeLDAPDisplayName=servicePrincipalName
 4ObjectClass=computer
 5NOT SubjectUserName="*$"
 6NOT SubjectUserSid IN (
 7    "S-1-5-18",
 8    "S-1-5-19",
 9    "S-1-5-20"
10)
11NOT SubjectUserName IN (
12    "*ANONYMOUS*",
13    "*NT AUTHORITY*",
14    "*SYSTEM"
15)
16
17
18| stats count min(_time) as firstTime
19              max(_time) as lastTime
20              values(AttributeValue) as spn_values
21              values(OperationType) as operation_types
22  by Computer SubjectUserName SubjectDomainName SubjectUserSid ObjectDN
23
24
25| eval operation_types=mvmap(operation_types, case(operation_types="%%14675", "Deleted", operation_types="%%14674", "Added", true(), operation_types))
26
27
28| rename Computer as dest
29
30
31| `security_content_ctime(firstTime)`
32
33| `security_content_ctime(lastTime)`
34
35| `windows_ad_computer_spn_modified_by_user_account_filter`

Data Source

Name Platform Sourcetype Source
Windows Event Log Security 5136 Windows icon Windows 'XmlWinEventLog' 'XmlWinEventLog:Security'

Macros Used

Name Value
security_content_ctime convert timeformat="%Y-%m-%dT%H:%M:%S" ctime($field$)
windows_ad_computer_spn_modified_by_user_account_filter search *
windows_ad_computer_spn_modified_by_user_account_filter is an empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.

Annotations

- MITRE ATT&CK
+ Kill Chain Phases
+ NIST
+ CIS
- Threat Actors
ID Technique Tactic
T1558.003 Kerberoasting Credential Access
T1562.010 Downgrade Attack Stealth
Exploitation
DE.AE
CIS 10

CVE

Default Configuration

This detection is configured by default in Splunk Enterprise Security to run with the following settings:

Setting Value
Disabled true
Cron Schedule 0 * * * *
Earliest Time -70m@m
Latest Time -10m@m
Schedule Window auto
Creates Finding (Notable) No
Creates Intermediate Finding (Risk Event) Yes
Anomaly detections generate Intermediate Findings (Risk Events). They do not generate a Finding (Notable) directly.

Implementation

To successfully implement this search, you need to be ingesting Domain Controller Security event logs. Enable the Advanced Security Audit policy DS Access > Audit Directory Service Changes for Success events. A WriteProperty audit SACL must also be configured on the computer object class (or CN=Computers container with inheritance) to generate Event 5136 when servicePrincipalName is modified.

Known False Positives

Administrators using tools such as setspn.exe, ADSI Edit, or PowerShell AD modules to manually manage SPNs on computer objects will trigger this detection. Service account provisioning workflows and some third-party identity management platforms may also legitimately modify computer SPNs. Review the SubjectUserName, ObjectDN, and spn_values fields to determine if the change is expected. Consider adding known administrative accounts to the filter macro.

Associated Analytic Story

Intermediate Findings

Message Entity Field Entity Type Risk Score
User [$SubjectUserName$] modified SPNs on computer object [$ObjectDN$] on $dest$ SubjectUserName user 20

Threat Objects

Field Type
SubjectUserName user

References

Detection Testing

Test Type Status Dataset Source Sourcetype
Validation ✅ Passing N/A N/A N/A
Unit ✅ Passing Dataset XmlWinEventLog:Security XmlWinEventLog
Integration ✅ Passing Dataset XmlWinEventLog:Security XmlWinEventLog

Replay any dataset to Splunk Enterprise by using our replay.py tool or the UI. Alternatively you can replay a dataset into a Splunk Attack Range


Source: GitHub |

Version: 1