Windows AD Computer SPN Modified By User Account
Description
The following analytic detects a user account (non-machine account) adding or removing a servicePrincipalName (SPN) on a computer object in Active Directory, via Windows Security Event 5136. In normal AD operations, SPN values on computer objects are managed exclusively by the computer account itself (during domain join or name change), by Domain Controllers during replication, or by the SYSTEM/NETWORK SERVICE context — all of which appear as accounts ending in the dollar sign ($) convention. A named user account writing to the servicePrincipalName attribute of a computer object is anomalous and may indicate an attacker with delegated WriteProperty rights over computer accounts performing SPN manipulation.
Query · spl
`wineventlog_security`
EventCode=5136
AttributeLDAPDisplayName=servicePrincipalName
ObjectClass=computer
NOT SubjectUserName="*$"
NOT SubjectUserSid IN (
"S-1-5-18",
"S-1-5-19",
"S-1-5-20"
)
NOT SubjectUserName IN (
"*ANONYMOUS*",
"*NT AUTHORITY*",
"*SYSTEM"
)
| stats count min(_time) as firstTime
max(_time) as lastTime
values(AttributeValue) as spn_values
values(OperationType) as operation_types
by Computer SubjectUserName SubjectDomainName SubjectUserSid ObjectDN
| eval operation_types=mvmap(operation_types, case(operation_types="%%14675", "Deleted", operation_types="%%14674", "Added", true(), operation_types))
| rename Computer as dest
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `windows_ad_computer_spn_modified_by_user_account_filter`
Implementation guide
To successfully implement this search, you need to be ingesting Domain Controller Security event logs. Enable the Advanced Security Audit policy DS Access > Audit Directory Service Changes for Success events. A WriteProperty audit SACL must also be configured on the computer object class (or CN=Computers container with inheritance) to generate Event 5136 when servicePrincipalName is modified.
Known false positives
- Administrators using tools such as setspn.exe, ADSI Edit, or PowerShell AD modules to manually manage SPNs on computer objects will trigger this detection. Service account provisioning workflows and some third-party identity management platforms may also legitimately modify computer SPNs. Review the SubjectUserName, ObjectDN, and spn_values fields to determine if the change is expected. Consider adding known administrative accounts to the filter macro.
Analyst notes
Known false positives: Administrators using tools such as setspn.exe, ADSI Edit, or PowerShell AD modules to manually manage SPNs on computer objects will trigger this detection. Service account provisioning workflows and some third-party identity management platforms may also legitimately modify computer SPNs. Review the SubjectUserName, ObjectDN, and spn_values fields to determine if the change is expected. Consider adding known administrative accounts to the filter macro.