heroui logo

Windows AD User Suspicious UPN Change

Splunk Security Content

View Source
Summary
This analytic detects a user modifying their own UserPrincipalName (UPN) via Windows Security Event 4738. It filters for self-modifications (SubjectUserSid = TargetSid) where the new UPN value is non-standard (no @ sign) and not a Windows placeholder. This pattern aligns with the initial step of the ResetNightmare attack (CVE-2026-27912), where an attacker with WriteProperty rights on their own UPN spoofs a target account to facilitate Kerberos-based credential theft. The detection relies on Domain Controllers emitting 4738 events and requires the Advanced Security Audit policy for User Account Management to be enabled. The rule aggregates by destination and relevant user fields and surfaces time bounds for investigation. It is intended to surface anomalous identity changes with no legitimate admin-use case and should be correlated with broader AD activity to confirm risk, as provisioning or migration workflows may legitimately set atypical UPN values. The technique maps to Kerberos/AD abuse patterns similar to Privilege Escalation via Valid Accounts (T1078.002).
Categories
  • Endpoint
  • Windows
  • Identity Management
Data Sources
  • Active Directory
ATT&CK Techniques
  • T1078.002
Created: 2026-10-01