Elastic high stable kql

Sensitive Privilege SeEnableDelegationPrivilege assigned to a Principal

Identifies the assignment of the SeEnableDelegationPrivilege sensitive "user right" to a security principal. This right enables computer and user accounts to be trusted for delegation. Attackers can abuse it to compromise Active Directory accounts and elevate their privileges.

View Source

Detection Logic

event.code:4704 and host.os.type:"windows" and winlog.event_data.PrivilegeList:"SeEnableDelegationPrivilege"

Field Validations

Loading…

Comments (0)

Loading comments...