| ID | Technique | Tactic |
|---|---|---|
| T1558.003 | Kerberoasting | Credential Access |
| T1562.010 | Downgrade Attack | Stealth |
Detection: Windows AD Computer SPN Modified By User Account
Description
The following analytic detects a user account (non-machine account) adding or removing a servicePrincipalName (SPN) on a computer object in Active Directory, via Windows Security Event 5136. In normal AD operations, SPN values on computer objects are managed exclusively by the computer account itself (during domain join or name change), by Domain Controllers during replication, or by the SYSTEM/NETWORK SERVICE context — all of which appear as accounts ending in the dollar sign ($) convention. A named user account writing to the servicePrincipalName attribute of a computer object is anomalous and may indicate an attacker with delegated WriteProperty rights over computer accounts performing SPN manipulation.
Search
1`wineventlog_security`
2EventCode=5136
3AttributeLDAPDisplayName=servicePrincipalName
4ObjectClass=computer
5NOT SubjectUserName="*$"
6NOT SubjectUserSid IN (
7 "S-1-5-18",
8 "S-1-5-19",
9 "S-1-5-20"
10)
11NOT SubjectUserName IN (
12 "*ANONYMOUS*",
13 "*NT AUTHORITY*",
14 "*SYSTEM"
15)
16
17
18| stats count min(_time) as firstTime
19 max(_time) as lastTime
20 values(AttributeValue) as spn_values
21 values(OperationType) as operation_types
22 by Computer SubjectUserName SubjectDomainName SubjectUserSid ObjectDN
23
24
25| eval operation_types=mvmap(operation_types, case(operation_types="%%14675", "Deleted", operation_types="%%14674", "Added", true(), operation_types))
26
27
28| rename Computer as dest
29
30
31| `security_content_ctime(firstTime)`
32
33| `security_content_ctime(lastTime)`
34
35| `windows_ad_computer_spn_modified_by_user_account_filter`
Data Source
| Name | Platform | Sourcetype | Source |
|---|---|---|---|
| Windows Event Log Security 5136 | 'XmlWinEventLog' |
'XmlWinEventLog:Security' |
Macros Used
| Name | Value |
|---|---|
| security_content_ctime | convert timeformat="%Y-%m-%dT%H:%M:%S" ctime($field$) |
| windows_ad_computer_spn_modified_by_user_account_filter | search * |
windows_ad_computer_spn_modified_by_user_account_filter is an empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
Annotations
CVE
Default Configuration
This detection is configured by default in Splunk Enterprise Security to run with the following settings:
| Setting | Value |
|---|---|
| Disabled | true |
| Cron Schedule | 0 * * * * |
| Earliest Time | -70m@m |
| Latest Time | -10m@m |
| Schedule Window | auto |
| Creates Finding (Notable) | No |
| Creates Intermediate Finding (Risk Event) | Yes |
Implementation
To successfully implement this search, you need to be ingesting Domain Controller Security event logs. Enable the Advanced Security Audit policy DS Access > Audit Directory Service Changes for Success events. A WriteProperty audit SACL must also be configured on the computer object class (or CN=Computers container with inheritance) to generate Event 5136 when servicePrincipalName is modified.
Known False Positives
Administrators using tools such as setspn.exe, ADSI Edit, or PowerShell AD modules to manually manage SPNs on computer objects will trigger this detection. Service account provisioning workflows and some third-party identity management platforms may also legitimately modify computer SPNs. Review the SubjectUserName, ObjectDN, and spn_values fields to determine if the change is expected. Consider adding known administrative accounts to the filter macro.
Associated Analytic Story
Intermediate Findings
| Message | Entity Field | Entity Type | Risk Score |
|---|---|---|---|
| User [$SubjectUserName$] modified SPNs on computer object [$ObjectDN$] on $dest$ | SubjectUserName | user | 20 |
Threat Objects
| Field | Type |
|---|---|
| SubjectUserName | user |
References
-
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-25177
-
https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-5136
Detection Testing
| Test Type | Status | Dataset | Source | Sourcetype |
|---|---|---|---|---|
| Validation | ✅ Passing | N/A | N/A | N/A |
| Unit | ✅ Passing | Dataset | XmlWinEventLog:Security |
XmlWinEventLog |
| Integration | ✅ Passing | Dataset | XmlWinEventLog:Security |
XmlWinEventLog |
Replay any dataset to Splunk Enterprise by using our replay.py tool or the UI.
Alternatively you can replay a dataset into a Splunk Attack Range
Source: GitHub |
Version: 1