
Summary
The rule detects the addition of a servicePrincipalName (SPN) on an Active Directory computer object that contains invisible Unicode characters, observed via Windows Security Event 5136 when the SPN attribute is modified. This mirrors the KerberLoss activity described for CVE-2026-25177, where an attacker with write access can inject a collision SPN that appears identical but includes zero-width or other invisible characters, circumventing LDAP’s string normalization (RFC 4518) during uniqueness checks. The Kerberos KDC, however, does not apply the same normalization and may return KDC_ERR_S_PRINCIPAL_UNKNOWN when two accounts share the same SPN, potentially causing Kerberos denial-of-service or forcing NTLM fallback. The analytic searches Domain Controllers for EventCode 5136 where AttributeValue is being changed for AttributeLDAPDisplayName=servicePrincipalName and OperationType indicates a SPN modification. It then applies a regex to AttributeValue to identify a defined set of invisible or zero-width characters (e.g., U+200C, U+200B, U+034F, U+FEFF, etc.). It records the matched characters, renames the source Computer to dest, and aggregates by dest, SubjectUserName, ObjectDN, ObjectClass, and AttributeValue to surface the first/last times of matching activity. The rule requires ingestion of DC security logs and proper auditing: Advanced Security Audit policy DS Access > Audit Directory Service Changes for Success, along with a WriteProperty SACL on computer objects to generate Event 5136 on SPN changes. When triggered, the finding highlights a potential Kerberos-related collision attempt and aligns with Active Directory Kerberos abuse scenarios, including possible persistence or escalation paths implied by the CVE and MITRE technique mappings.
Categories
- Endpoint
- Windows
- Identity Management
Data Sources
- Application Log
ATT&CK Techniques
- T1562.010
Created: 2026-10-05