๐๐ข๐๐ซ๐จ๐ฌ๐จ๐๐ญ ๐๐๐๐๐ง๐๐๐ซ ๐๐จ๐ซ ๐๐๐๐ง๐ญ๐ข๐ญ๐ฒ ๐๐ฑ๐ฉ๐๐ง๐๐ฌ ๐ข๐ญ๐ฌ ๐๐จ๐ฏ๐๐ซ๐๐ ๐ ๐ฐ๐ข๐ญ๐ก ๐ง๐๐ฐ ๐๐ ๐๐ ๐ฌ๐๐ง๐ฌ๐จ๐ซ
Sensor that can be deployed on Active Directory Certificate Services (AD CS) servers. This new sensor builds on the existing detections for suspicious certificate usage available today and extends Defender for Identities capabilities and coverage more comprehensively across identity environments.
AD CS is a role in Windows Server that allows you to create and manage public key infrastructure (PKI) certificates.
New detections:
โก๏ธDomain-controller certificate issuance for a non-DC
โก๏ธSuspicious disable of audit logs of AD CS
โก๏ธSuspicious deletion of the certificate database
โก๏ธSuspicious modifications to the AD CS settings (coming soon)
#defenderforidentity #xdr #mdi #azure #microsoft #micrsoftsecurity #soc #adcs #pki #windows #server #cybersecurity #microsoft365defender #cloudsecurity #identity