LoFP LoFP / modifications in the msds-keycredentiallink attribute can be done legitimately by the azure ad connect synchronization account or the adfs service account. these accounts can be added as exceptions. (from elastic fp section)

Techniques

Sample rules

Possible Shadow Credentials Added

Description

Detects possible addition of shadow credentials to an active directory object.

Detection logic

condition: selection
selection:
  AttributeLDAPDisplayName: msDS-KeyCredentialLink
  EventID: 5136