Windows AD Suspicious Attribute Modification (Enhanced)

Detects modification of sensitive Active Directory LDAP attributes (msDS-AllowedToDelegateTo, msDS-AllowedToActOnBehalfOfOtherIdentity, scriptPath, msTSInitialProgram, msDS-KeyCredentialLink) via Windows Security EventCode 5136, and correlates the initiating session back to its originating logon (EventCode 4624) to surface the actor's SID, domain, source IP, and logon host. These attributes are commonly abused for Kerberos delegation abuse (constrained/resource-based constrained delegation), logon-script/Terminal-Services persistence, and Shadow Credentials (msDS-KeyCredentialLink) attacks. Includes anchor fields (initiator SID, domain controller, distinct-attribute count, operation correlation ID) to support precise, low-blast-radius tuning instead of broad exclusions.

Splunk (SPL)