This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Azure AD Health Monitoring Agent Registry Keys Access
Original Source:
[Sigma source]
Title:
Azure AD Health Monitoring Agent Registry Keys Access
Status:
test
Description:
This detection uses Windows security events to detect suspicious access attempts to the registry key of Azure AD Health monitoring agent. This detection requires an access control entry (ACE) on the system access control list (SACL) of the following securable object HKLM\SOFTWARE\Microsoft\Microsoft Online\Reporting\MonitoringAgent.
References:
-https://o365blog.com/post/hybridhealthagent/
-https://github.com/OTRF/Set-AuditRule/blob/c3dec5443414231714d850565d364ca73475ade5/rules/registry/aad_connect_health_monitoring_agent.yml
Author:
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), MSTIC
Date:
2021-08-26
modified:
2022-10-09
Tags:
-'attack.discovery'
-'attack.t1012'
Logsource:
product: windows
service: security
Detection:
selection:
EventID
:
-'4656'
-'4663'
ObjectType
:
'Key'
ObjectName
:
'\REGISTRY\MACHINE\SOFTWARE\Microsoft\Microsoft Online\Reporting\MonitoringAgent'
filter:
ProcessName|contains
:
-'Microsoft.Identity.Health.Adfs.DiagnosticsAgent.exe'
-'Microsoft.Identity.Health.Adfs.InsightsService.exe'
-'Microsoft.Identity.Health.Adfs.MonitoringAgent.Startup.exe'
-'Microsoft.Identity.Health.Adfs.PshSurrogate.exe'
-'Microsoft.Identity.Health.Common.Clients.ResourceMonitor.exe'
condition
:
selection and not filter
Falsepositives:
-Unknown
Level:
medium