Techniques
Sample rules
Windows AD User Suspicious UPN Change
- source: splunk
- technicques:
Description
The following analytic detects a user account modifying its own userPrincipalName (UPN) to match the sAMAccountName of another account via Windows Security Event 4738. This is the setup step of the ResetNightmare attack (CVE-2026-27912), where an attacker with WriteProperty rights on their own UPN attribute spoofs their identity to a target account. The KDC then resolves a ptype=10 (NT-ENTERPRISE) Kerberos pre-authentication request against the spoofed UPN, issuing a kadmin/changepw TGT that can be used to change the target account’s password via kpasswd (port 464). Event 4738 is generated when a user account attribute is changed. This analytic filters to events where the SubjectUserSid equals the TargetSid (self-modification), the new UPN value is not a standard UPN (no @ sign), and the value is not a Windows placeholder. A non-UPN value set on one’s own account is anomalous and has no legitimate administrative use case.
Detection logic
`wineventlog_security`
EventCode=4738
UserPrincipalName="*"
NOT UserPrincipalName IN (
"-",
"",
"*@*",
"%%1793"
)
NOT SubjectUserSid IN (
"S-1-5-18",
"S-1-5-7"
)
NOT SubjectUserName IN (
"ANONYMOUS*",
"NT AUTHORITY*"
)
| where SubjectUserSid=TargetSid
| stats count min(_time) as firstTime
max(_time) as lastTime
by dest SubjectUserName SubjectUserSid TargetUserName TargetSid UserPrincipalName
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `windows_ad_user_suspicious_upn_change_filter`