Techniques
Sample rules
Possible Shadow Credentials Added
- source: sigma
- technicques:
- t1556
Description
Detects possible addition of shadow credentials to an active directory object.
Detection logic
condition: selection
selection:
AttributeLDAPDisplayName: msDS-KeyCredentialLink
EventID: 5136