ππ’ππ«π¨π¬π¨ππ πππππ§πππ« ππ¨π« ππππ§ππ’ππ² ππ±π©ππ§ππ¬ π’ππ¬ ππ¨π―ππ«ππ π π°π’ππ‘ π§ππ° ππ ππ π¬ππ§π¬π¨π«
Sensor that can be deployed on Active Directory Certificate Services (AD CS) servers. This new sensor builds on the existing detections for suspicious certificate usage available today and extends Defender for Identities capabilities and coverage more comprehensively across identity environments.
AD CS is a role in Windows Server that allows you to create and manage public key infrastructure (PKI) certificates.
New detections:
β‘οΈDomain-controller certificate issuance for a non-DC
β‘οΈSuspicious disable of audit logs of AD CS
β‘οΈSuspicious deletion of the certificate database
β‘οΈSuspicious modifications to the AD CS settings (coming soon)
https://techcommunity.microsoft.com/t5/microsoft-365-defender-blog/microsoft-defender-for-identity-expands-its-coverage-with-new-ad/ba-p/3894215
#defenderforidentity #xdr #mdi #azure #microsoft #micrsoftsecurity #soc #adcs #pki #windows #server #cybersecurity #microsoft365defender #cloudsecurity #identity