
Summary
This anomaly rule detects when a non-machine user account writes to the servicePrincipalName (SPN) attribute on a computer object in Active Directory by monitoring Windows Security Event 5136 (Directory Service Changes). Under normal operations, SPN management for computer objects is performed by the computer account itself (during domain join or name changes), by Domain Controllers during replication, or by system contexts (e.g., SYSTEM/NETWORK SERVICE) — all of which appear with dollar-sign ending names. A named user performing SPN modifications on a computer object is anomalous and may indicate an attacker with delegated WriteProperty rights manipulating SPNs to enable Kerberos abuse or persistence. The rule ingests Domain Controller Security event logs and filters for AttributeLDAPDisplayName=servicePrincipalName and ObjectClass=computer, while excluding common legitimate accounts (e.g., accounts ending in $, well-known service accounts, anonymous or SYSTEM). It aggregates by Computer (dest), SubjectUserName, SubjectDomainName, SubjectUserSid, and ObjectDN, collecting spn_values and operation_types. Operation types are normalized to show Added or Deleted SPN modifications. The rule then renames Computer to dest and renders firstTime/lastTime in a human-readable form. It relies on a predefined search macro and filter (windows_ad_computer_spn_modified_by_user_account_filter) to surface concise, actionable findings with context (SubjectUserName, ObjectDN, spn_values). For operational deployment, you must enable Domain Controller auditing for Directory Service Changes (DS Access > Audit Directory Service Changes) and configure a WriteProperty SACL on computer objects (or the Computers container with inheritance) so that Event 5136 is emitted when SPNs are modified. False positives typically include administrative actions (setspn.exe, ADSI Edit, PowerShell AD modules) and legitimate provisioning workflows; reviewers should examine SubjectUserName, ObjectDN, and SPN values and consider adding trusted admin accounts to the filter. References include guidance on SPN vulnerabilities, Microsoft advisories, and Windows auditing, along with related CVE and ATT&CK mappings. The rule supports incident response and threat hunting for AD Kerberos abuse, compromised user accounts, and persistence techniques, and is linked to MITRE tactics T1562.010 and T1558.003. It also maps to a CVE reference and provides targeted drilldown paths for analysis. A True Positive test is included to validate detection against representative Kerberos-related SPN modifications.
Categories
- Windows
- Endpoint
Data Sources
- Active Directory
ATT&CK Techniques
- T1562.010
- T1558.003
Created: 2026-10-05