[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.com/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/)  
Menu

* [Tools](https://unit42.paloaltonetworks.com/tools/)
* [ATOMs](https://unit42.paloaltonetworks.com/atoms/)
* [Security Consulting](https://www.paloaltonetworks.com/unit42)
* [About Us](https://unit42.paloaltonetworks.com/about-unit-42/)
* [**Under Attack?**](https://start.paloaltonetworks.com/contact-unit42.html)
* [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research")
* [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/ "Threat Research")
* [Vulnerabilities](https://unit42.paloaltonetworks.com/category/vulnerabilities/ "Vulnerabilities")  
  [Vulnerabilities](https://unit42.paloaltonetworks.com/category/vulnerabilities/)

# When Good Accounts Go Bad: Exploiting Delegated Managed Service Accounts in Active Directory

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 18 min read  
Related Products  
[![Cortex icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/cortex_RGB_logo_Icon_Color.png)Cortex](https://unit42.paloaltonetworks.com/product-category/cortex/ "Cortex")[![Cortex XDR icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/cortex_RGB_logo_Icon_Color.png)Cortex XDR](https://unit42.paloaltonetworks.com/product-category/cortex-xdr/ "Cortex XDR")[![Cortex XSIAM icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/cortex_RGB_logo_Icon_Color.png)Cortex XSIAM](https://unit42.paloaltonetworks.com/product-category/cortex-xsiam/ "Cortex XSIAM")[![Unit 42 Incident Response icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/unit42_RGB_logo_Icon_Color.png)Unit 42 Incident Response](https://unit42.paloaltonetworks.com/product-category/unit-42-incident-response/ "Unit 42 Incident Response")

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  By:
  
  * [Noam Sala](https://unit42.paloaltonetworks.com/author/noam-sala/)
  * [Paul Michaud II](https://unit42.paloaltonetworks.com/author/paul-michaud-ii/)
  * [Ofir Shlomo](https://unit42.paloaltonetworks.com/author/ofir-shlomo/)

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  Published:August 6, 2025

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  Categories:
  
  * [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/)
  * [Vulnerabilities](https://unit42.paloaltonetworks.com/category/vulnerabilities/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  Tags:
  
  * [Active Directory](https://unit42.paloaltonetworks.com/tag/active-directory/)
  * [Microsoft](https://unit42.paloaltonetworks.com/tag/microsoft/)
  * [PowerShell](https://unit42.paloaltonetworks.com/tag/powershell/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/badsuccessor-attack-vector/?pdf=download&lg=en&_wpnonce=1628116e08 "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/badsuccessor-attack-vector/?pdf=print&lg=en&_wpnonce=1628116e08 "Click here to print")

Share![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](mailto:?subject=When%20Good%20Accounts%20Go%20Bad:%20Exploiting%20Delegated%20Managed%20Service%20Accounts%20in%20Active%20Directory&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fbadsuccessor-attack-vector%2F "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Fbadsuccessor-attack-vector%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fbadsuccessor-attack-vector%2F&title=When%20Good%20Accounts%20Go%20Bad:%20Exploiting%20Delegated%20Managed%20Service%20Accounts%20in%20Active%20Directory "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fbadsuccessor-attack-vector%2F&text=When%20Good%20Accounts%20Go%20Bad:%20Exploiting%20Delegated%20Managed%20Service%20Accounts%20in%20Active%20Directory "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fbadsuccessor-attack-vector%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](https://mastodon.social/share?text=When%20Good%20Accounts%20Go%20Bad:%20Exploiting%20Delegated%20Managed%20Service%20Accounts%20in%20Active%20Directory%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fbadsuccessor-attack-vector%2F "Share in Mastodon")

## Executive Summary

BadSuccessor is a critical attack vector that emerged following the release of Windows Server 2025. Under certain conditions, this server version enables users to leverage delegated Managed Service Accounts (dMSAs) to elevate privileges within Active Directory environments running Windows Server 2025. At the time of writing this article, no patch exists for this issue.

By analyzing the core mechanics of this technique and offering practical detection strategies, we help security professionals and system administrators understand dMSAs and how attackers can misuse them to elevate privileges. We also provide advice on how to implement effective detection and mitigation strategies.

Palo Alto Networks customers are better protected against the BadSuccessor technique through [Cortex XDR](https://docs-cortex.paloaltonetworks.com/p/XDR) and [XSIAM](https://docs-cortex.paloaltonetworks.com/p/XSIAM). These products already have the ability to detect the attack. Performing auditing on the delegated Managed Service Account is a required action that we describe in this article.

The [Unit 42 Managed Detection and Response Service](https://www.paloaltonetworks.com/resources/datasheets/unit42-managed-detection-and-response) can assist with threat detection, investigation and response/remediation.

The [Unit 42 Incident Response team](https://start.paloaltonetworks.com/contact-unit42.html) can also be engaged to help with a compromise or to provide a proactive assessment to lower your risk.

| **Related Unit 42 Topics** | [**Microsoft**](https://unit42.paloaltonetworks.com/tag/microsoft/), **[Active Directory](https://unit42.paloaltonetworks.com/tag/active-directory/)** |
|----------------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------|

## BadSuccessor Overview

BadSuccessor is a novel technique that enables a threat actor with sufficient privileges to compromise an Active Directory (AD) domain by misusing controlled delegated Managed Service Account (dMSA) objects.

Originally detailed in [research published by Akamai](https://www.akamai.com/blog/security-research/abusing-dmsa-for-privilege-escalation-in-active-directory), this technique demonstrates how modifying a small set of attributes on a dMSA object under the attacker's control can lead to privilege escalation within the environment. Publicly available tools have already been released to automate various steps involved in leveraging this technique, potentially lowering the barrier for its adoption.

We provide a comprehensive breakdown of the attack methodology, along with guidance on detection strategies and potential mitigations.

## Understanding dMSAs

### The Evolution of MSAs

Windows has [two basic types of accounts](https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-authsod/5bb3e0c3-f6c1-4e2c-8c6d-0f54553b4ed9):

* Machine accounts
* User accounts

In an AD environment, machine accounts represent hosts (servers or clients) that belong to a domain, while user accounts represent the users who log into and access the environment.

Service accounts are user accounts or machine accounts that [provide a security context for services running on a Windows Server](https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/manage/understand-service-accounts). In other words, Windows services authenticate with service accounts. Windows relies on service accounts to run its various features.

With the release of Windows Server 2008 R2, Microsoft introduced Managed Service Accounts (MSAs) and group Managed Service Accounts (gMSAs) to simplify and enhance AD service account management.

MSAs and gMSAs are specialized service accounts designed to securely run services within an AD environment without the need for manual password handling. An MSA account is linked to a single computer, allowing only that machine to retrieve and use the account. Conversely, a gMSA account can be used by multiple computers, like clusters or server farms.

A key benefit of MSAs and gMSAs is that AD automatically manages their passwords. This involves generating strong, unique passwords and rotating them regularly, eliminating the need for human administrators to manage credentials. For example, when a service needs to access a domain resource, the Local Security Authority Subsystem Service (LSASS) uses the machine account to securely request the MSA or gMSA's password. In this way, the password is handled in the AD and not directly by a user or an administrator.

### Delegated Managed Service Accounts

The dMSA is a new account type introduced in Windows Server 2025 to facilitate the migration of traditional service accounts to Managed Service Accounts. This process is as follows:

* An administrator creates a new dMSA object, which is intended to supersede the existing service account.
* The administrator then initiates the migration, which sets the dMSA msDS-ManagedAccountPrecededByLink attribute to reference the original service account.
* When the original service authenticates as the original service account, it triggers a Lightweight Directory Access Protocol (LDAP) modify request. This adds the machine account to the list of principals that are allowed to retrieve the dMSA password.
* In the final step, the administrator completes the migration, which disables the original service account. The service continues to operate seamlessly using the dMSA.
* Once a dMSA supersedes an existing account, any attempts to authenticate as that existing account using its password will be blocked. These authentication requests are redirected to the Local Security Authority (LSA) to authenticate using the dMSA. By then, the request has been granted all permissions that the original account had in the Active Directory, by the Key Distribution Center (KDC).

While dMSAs are intended to prevent credential harvesting, dMSAs also create a privilege escalation path that attackers can exploit through the BadSuccessor technique.

### dMSA Migration Flow

The migration process of a traditional service account to a dMSA is triggered by an administrator using the Start-ADServiceAccountMigration PowerShell AD module command. The administrator passes the following values to the command:

* The [Distinguished Name (DN)](https://learn.microsoft.com/en-us/previous-versions/windows/desktop/ldap/distinguished-names) of the intended dMSA account
* The DN of the superseded account

As the migration continues, it changes several attributes of the normal service account as it transitions to a dSMA account, including:

* The msDS-DelegatedMSAState attribute is set to 1 in the newly created dMSA.

This attribute indicates the current state of the dMSA. [Microsoft's documentation](https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/manage/delegated-managed-service-accounts/delegated-managed-service-accounts-overview#account-attributes-for-dmsa) shows that 1 means the account migration has begun.

* The dMSA's msDS-ManagedAccountPrecededByLink attribute is set to reference the superseded account.

Next, the administrator initiates the Complete-ADServiceAccountMigration command. This command disables the superseded account, and it changes the msDS-DelegatedMSAState and msDS-SupersededServiceAccountState attribute values of the dMSA object to 2, indicating that the migration is complete.

Following this migration, any service that relies on the superseded account will use the dMSA instead, which now has all the permissions that the superseded account had.

## Technical Analysis: Bad Successor Technique and Tools

This section demonstrates how attackers can use dMSAs to impersonate any domain user account, including the domain administrator, using the BadSuccessor technique.

### dMSA Misuse

If an attacker or low-privileged user attempts to initiate the migration process for an existing service account, the operation will fail, because only administrative users can initiate migration. Instead of initiating the migration process, a potential attacker would create a dMSA and then change the same dMSA attributes that the valid migration process changes. This mimics a migration and has the same effect on the migrated account.

By default, only high-privileged users can create dMSAs under the default Managed Service Accounts container. However, other users can create dMSAs in other containers. This ultimately means that any domain user who has Create all child objects or msDS-DelegatedManagedServiceAccount permissions on an organizational unit (OU) could potentially compromise the entire domain.

The following steps detail how an attacker could simulate the migration:

* Set the msDS-ManagedAccountPrecededByLink attribute to contain the DN of the account the attacker wants to impersonate.
* Set msDS-DelegatedMSAState to 2, to indicate that the migration process is complete.

After changing these attributes and authenticating as the dMSA, the attacker obtains the full permissions of the superseded account.

Any user with sufficient permissions can execute this method in any AD environment managed by a Windows Server 2025 domain controller (DC).

### BadSuccessor Simulation

Before performing the actual attack, an attacker must ensure the compromised user has sufficient permissions to create all child objects or dMSAs. Akamai released a PowerShell script named [Get-BadSuccessorOUPermissions.ps1](https://github.com/akamai/BadSuccessor/blob/main/Get-BadSuccessorOUPermissions.ps1) that finds domain accounts that have the appropriate permissions on an OU to perform the BadSuccessor technique.

Figure 1 shows an example of Akamai's tool in action in a test AD environment. The output provides details of the objects in the domain that can be leveraged for BadSuccessor.
![Screen showing Windows PowerShell with a command executed to get AD user permissions, displaying results for a specific user from a domain.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/figure-1-execution-of-get-badsuccessoroupermissio.png) Figure 1. Executing Get-BadSuccessorOUPermissions.ps1 in our test environment.

In the example from Figure 1, the results indicate that an account named test\_weak has the correct permissions to create a dMSA object under the OU DelegatedOU.

The enumeration tool performs the command shown in Figure 2 to retrieve OU DNs and their security descriptors.
![Screenshot of computer code text related to a PowerShell command, highlighted in blue and purple.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/word-image-387568-149694-2.png) Figure 2. Command to retrieve OU DNs and their security descriptors.

After the tool retrieves the OU DNs and their security descriptors, it reviews the output to find the following rights:

* Create Child: msDS-DelegatedManagedServiceAccount
* Create Child: All Objects

The tool's output reveals all users and OU pairs that can potentially be leveraged for the BadSuccessor technique.

Using a newly found account with the required permissions, an adversary can potentially perform the BadSuccessor technique using [PowerShell's Active Directory Module](https://learn.microsoft.com/en-us/powershell/module/activedirectory/?view=windowsserver2025-ps) and [LDAP](https://learn.microsoft.com/en-us/previous-versions/windows/desktop/ldap/lightweight-directory-access-protocol-ldap-api), as described in the [Akamai article](https://www.akamai.com/blog/security-research/abusing-dmsa-for-privilege-escalation-in-active-directory).

* First, the attacker creates a dMSA under the found OU. We demonstrate this in Figure 3 by creating a dMSA object named attacker\_dMSA.

![Image depicts a computer code snippet on a dark background with text including PowerShell commands related to creating a new service account named "attacker\_0WSA" and managing DNS and computer settings.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/word-image-390092-149694-3.png) Figure 3. Commands to create a dMSA object under the found OU.

* Next, the attacker changes the attributes of the dMSA object to simulate the migration process. We demonstrated this in our test environment by setting the following values:
  * msDS-ManagedAccountPrecededByLink attribute to contain the DN of the superseded account
  * msDS-DelegatedMSAState to 2, to indicate that the migration process is complete

![Screenshot of computer code related to a dMSA object.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/word-image-393583-149694-4.png) Figure 4. Attributes of a dMSA object changed for the BadSuccessor technique.

Now that we know how the BadSuccessor technique works, let's explore how different tools can automate an attack.

### SharpSuccessor

[SharpSuccessor](https://github.com/logangoins/SharpSuccessor/tree/master) is a proof of concept (PoC) hosted on a GitHub repository that automates the BadSuccessor technique. Figure 5 simulates an attack using a user account named test\_weak in our test environment. This account has permissions to create a dMSA object under the DelegatedOU.
![Screenshot of SharpSuccessor execution displaying commands for a malware attack simulation including logging in, adding a domain, and attempting to write and access attributes.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/word-image-396203-149694-5.png) Figure 5. Execution of SharpSuccessor.

Figure 6 shows that the attacker\_dMSA account is subsequently created in the OU.
![Screenshot of the Active Directory Users and Computers management tool, displaying a list of folders including 'Users', 'Computers', and 'Domain Controllers.'](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/word-image-401049-149694-6.png) Figure 6. attacker\_dMSA created under DelegatedOU.

Figure 7 shows how test\_weak changed the msDS-ManagedAccountPrecededByLink and msDS-DelegatedMSAState attributes of attacker\_dMSA. This simulates the completion of the migration.
![Screenshot of a software dialog box titled "attacker\_dMSA Properties" displaying various system attributes and their corresponding values, primarily focused on security and user account settings. Two settings are highlighted.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/word-image-405182-149694-7.png) Figure 7. attacker\_dMSA attributes msDS-DelegatedMSAState and msDS-ManagedAccountPrecededByLink.

### Pentest-Tools-Collection BadSuccessor Module

The Pentest-Tools-Collection recently added a [BadSuccessor module](https://github.com/LuemmelSec/Pentest-Tools-Collection/blob/main/tools/ActiveDirectory/BadSuccessor.ps1) as one of its AD tools. This module has two modes:

* Check mode
* Exploit mode

Like the enumeration tool we previously discussed, this module's check mode enumerates an AD environment. This enumeration indicates whether the environment can be exploited using the BadSuccessor technique and what OU can be used for a successful attack.

Figure 8 shows the results of this module after we ran it in check mode in our test environment.
![Screenshot of PowerShell windows with queries being executed related to domain controls and system checks.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/word-image-409037-149694-8.png) Figure 8. Executing Pentest-Tools-Collection's BadSuccessor module in check mode.

This module's exploit mode creates a dMSA object and sets its attributes to falsely indicate that a migration process is complete. Figure 9 shows the use of this module in exploit mode automating the same BadSuccessor process previously shown in Figures 3 and 4.
![Command line interface showing the configuration of a user named 'test\_weak' being granted impersonation rights on an 'Administrator' account within a domain environment.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/word-image-413464-149694-9.png) Figure 9. Executing Pentest-Tools-Collection's BadSuccessor module in exploit mode.

### Domain Compromise

After successfully executing the BadSuccessor technique, potential attackers can further exploit the domain using Rubeus, which [supports dMSA authentication](https://www.akamai.com/blog/security-research/abusing-dmsa-for-privilege-escalation-in-active-directory#title-8738ec3891). Figure 10 illustrates some Rubeus commands using the attacker\_dMSA object in our test environment to gain access to privileged services in the domain.
![Screenshot of a computer terminal displaying commands related to Rubues.exe on a Windows system, specifically for requesting and applying Kerberos tickets, involving entities such as a user named 'attacker', and domains ending in 'env20.local'.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/word-image-416557-149694-10.png) Figure 10. Example of commands to use Rubeus to further exploit the domain in our test environment.

Figure 11 shows that after executing these Rubeus commands, test\_weak can now access the network share C$ drive on the DC, which requires Domain Admin privileges.
![Screenshot of a Windows command prompt display showing directory listings with dates and times for folders such as Program Files, Program Files (x86), and Users.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/word-image-419330-149694-11.png) Figure 11. test\_weak account accessing the DC's C$ directory using the attacker\_dMSA object in our test environment.

## Detecting BadSuccessor Activity

As presented in the [Akamai article](https://www.akamai.com/blog/security-research/abusing-dmsa-for-privilege-escalation-in-active-directory#title-971c0073d4), the operations involved in BadSuccessor can be monitored via the following event IDs:

* Event ID 5137 --- Tracks the creation of dMSA objects
* Event ID 5136 --- Tracks the modification of the msDS-ManagedAccountPrecededByLink attribute
* Event ID 2946 --- Tracks the Ticket Granting Ticket (TGT) that is generated for a dMSA

But we propose an alternative way to track BadSuccessor activity and the footprints that it leaves behind; by leveraging Event ID 4662.

When a user creates a dMSA object, the initiating user or process requires and uses the CreateChild [access rights](https://learn.microsoft.com/en-us/windows-hardware/drivers/kernel/access-rights) on the OU. Figure 12 shows how dMSA object creation using the CreateChild access rights is reflected in Event ID 4662 (An operation was performed on an object).
![Event Properties window showing details of event 4662, Microsoft Windows security auditing. Fields include Account Name, Security ID, Object Type, Handle ID, Operation Type, and other specific identifiers, highlighted with a red box around the Additional Information.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/word-image-423062-149694-12.png) Figure 12. Event ID 4662 that audits the dMSA creation.

The same Event ID is generated when a user with sufficient access rights modifies the following two attributes in the properties of the dMSA object.

* 2f5c138a-bd38-4016-88b4-0ec87cbb4919 represents msDS-DelegatedMSAState
* a0945b2b-57a2-43bd-b327-4d112a4e8bd1 represents msDS-ManagedAccountPrecededByLink

Changing the above dMSA attributes triggers the event shown in Figure 13.
![Event Properties window showing details of event 4662, Microsoft Windows security auditing. Fields include Account Name, Security ID, Object Type, Handle ID, Operation Type, and other specific identifiers, highlighted with a red box around the Security ID, Account Name, Access Mask, Properties and more.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/word-image-425751-149694-13.png) Figure 13. Event ID 4662 that audits the change to the dMSA's attributes.

### Legitimate dMSA Migration Process Footprints

To better detect BadSuccessor, we must also know the differences between the footprints of malicious dMSA activity and legitimate dMSA migration. Only Administrative users can legitimately migrate service accounts to dMSA objects. To detect BadSuccessor activity, we must search for unprivileged users who have created a dMSA and then accessed the object's specific attributes with the Access Mask value of 0x20 as shown in Figure 13.

A slightly different footprint is created when a privileged user creates a dMSA legitimately and then migrates a service account. According to [Microsoft's guide](https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/manage/delegated-managed-service-accounts/delegated-managed-service-accounts-set-up-dmsa), only a privileged user can create a dMSA under the OU Managed Service Account. The Event 4662 log entry in Figure 14 shows an Administrator user creating a child object (the dMSA) in the Managed Service Account OU.
![Event Properties window showing details of event 4662, Microsoft Windows security auditing.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/word-image-429017-149694-14.png) Figure 14. Event ID 4662 that documents the creation of a legitimate dMSA.

A legitimate migration uses an initial msDS-DelegatedMSAState attribute with a value of 1. Figure 15 shows that the msDS-DelegatedMSAState attribute was changed in the first step of the migration process, while Figure 16 shows it was changed to 1.
![Event Properties window showing details of event 4662, Microsoft Windows security auditing. A red box highlights the last item in the Properties list.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/word-image-433083-149694-15.png) Figure 15. Event ID 4662 that audits the first step of dMSA account migration, where the msDS-DelegatedMSAState attribute is changed. ![Screenshot of Microsoft Windows security auditing event detail, focusing on the LDAP Display Name 'msDs-DelegatedServiceAccount' with its value set to 1.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/word-image-436824-149694-16.png) Figure 16. Event ID 5136 that audits the change of the msDS-DelegatedMSAState dMSA object attribute to 1.

Figure 17 shows the last step that consists of changing the msDS-DelegatedMSAState attribute to 2, and changing the msDS-ManagedAccountPrecededByLink attribute to the superseded account.
![Event Properties window showing details of a security audit for Event 4662. The object accessed is managed by the account "ENVO\\Administrator" and the operation involved writing properties. A specific GUID identifier is highlighted in red.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/word-image-440973-149694-17.png) Figure 17. Event ID 4662 that audits the changes made to the msDS-DelegatedMSAState and msDS-ManagedAccountPrecededByLink attributes.

### Enabling Auditing

To identify the attack footprint and conduct detection activities, auditing must be enabled. Figure 18 shows an example of a relevant auditing interface.
![Screenshot of a computer interface for managing user permissions with various options for types of permissions like 'Read all' and 'Modify permissions', and an arrow pointing to a dropdown list labeled 'Assign to' with the selected option.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/word-image-444423-149694-18.png) Figure 18. Example of auditing enablement on Windows Server 2025.

## Conclusion

We examined the BadSuccessor technique and explored how, under certain conditions, adversaries can exploit the newly introduced dMSAs in a Windows Server 2025 DC to compromise the domain. We also analyzed the operational footprints left by this activity and proposed a novel detection strategy to identify such attacks.

Given how effective this attack can be, we strongly recommend closely monitoring Microsoft's updates to understand available mitigation strategies and to properly configure all permissions --- particularly those related to the BadSuccessor attack.

### Palo Alto Networks Protections

Palo Alto Networks customers can leverage a variety of product protections and updates to identify and defend against this threat.

One such product is Palo Alto Networks [XSIAM](https://docs-cortex.paloaltonetworks.com/p/XSIAM), which can detect BadSuccessor activity if Windows security auditing is enabled on the dMSA. Our [security auditing guide for Microsoft Windows systems](https://docs-cortex.paloaltonetworks.com/r/Cortex-XSIAM/Cortex-XSIAM-Documentation/Microsoft-Windows-security-auditing-setup) provides information on how to configure the [required auditing](https://docs-cortex.paloaltonetworks.com/r/Cortex-XSIAM/Cortex-XSIAM-Documentation/Enable-auditing-access-to-AD-domain-objects-4662) on Windows Server 2025.

Figure 19 shows an example of a "Possible Privilege Escalation using delegated MSA account attempt" in XSIAM.
![Screenshot of Cortex XDR cybersecurity dashboard displaying details about a potential Privilege Escalation incident using Delegated MSA account in a Windows environment. Information includes alerts, user data, timestamps, and MITRE ATT\&CK tactics related to credential manipulation.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/word-image-447143-149694-19.png) Figure 19. Example of a Cortex XDR alert for "Possible privilege escalation using delegated MSA account attempt."

[Cortex XDR](https://docs-cortex.paloaltonetworks.com/p/XDR) and [XSIAM](https://docs-cortex.paloaltonetworks.com/p/XSIAM) detect user and credential-based threats by analyzing user activity from multiple data sources including endpoints, network firewalls, AD, identity and access management solutions, and cloud workloads. Cortex builds behavioral profiles of user activity over time with machine learning. By comparing new activity to past activity, peer activity and the expected behavior of the entity, Cortex detects anomalous activity indicative of credential-based attacks.

[Unit 42 Managed Detection and Response Service](https://www.paloaltonetworks.com/resources/datasheets/unit42-managed-detection-and-response) delivers continuous 24/7 threat detection, investigation and response/remediation to customers of all sizes globally.

If you think you might have been compromised or have an urgent matter, get in touch with the [Unit 42 Incident Response team](https://start.paloaltonetworks.com/contact-unit42.html) or call:

* North America: Toll Free: +1 (866) 486-4842 (866.4.UNIT42)
* UK: +44.20.3743.3660
* Europe and Middle East: +31.20.299.3130
* Asia: +65.6983.8730
* Japan: +81.50.1790.0200
* Australia: +61.2.4062.7950
* India: 00080005045107

Palo Alto Networks has shared our findings with our fellow Cyber Threat Alliance (CTA) members. CTA members use this intelligence to rapidly deploy protections to their customers and to systematically disrupt malicious cyber actors. Learn more about the [Cyber Threat Alliance](https://www.cyberthreatalliance.org/).

## Additional Resources

### BadSuccessor

* [BadSuccessor: Abusing dMSA to Escalate Privileges in Active Directory](https://www.akamai.com/blog/security-research/abusing-dmsa-for-privilege-escalation-in-active-directory) --- Akamai
* [Setting up delegated Managed Service Accounts](https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/manage/delegated-managed-service-accounts/delegated-managed-service-accounts-set-up-dmsa) --- Microsoft
* [Account attributes for dMSA](https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/manage/delegated-managed-service-accounts/delegated-managed-service-accounts-overview) --- Microsoft

### Enabling Auditing

* [Enable auditing access to AD domain objects --- 4662](https://docs-cortex.paloaltonetworks.com/r/Cortex-XSIAM/Cortex-XSIAM-Documentation/Enable-auditing-access-to-AD-domain-objects-4662) --- Palo Alto Networks

### Tools

* [Get-BadSuccessorOUPermissions.ps1](https://github.com/akamai/BadSuccessor/blob/main/Get-BadSuccessorOUPermissions.ps1) --- GitHub
* [SharpSuccessor](https://github.com/logangoins/SharpSuccessor/tree/master) --- GitHub
* [NetExec BadSuccessor module](https://github.com/Pennyw0rth/NetExec/blob/main/nxc/modules/badsuccessor.py) --- GitHub

## Appendix

### Unit 42 Managed Threat Hunting Queries

The Unit 42 Managed Threat Hunting team has created queries that can help defenders identify potential signs of dMSA misuse and use of SharpSuccessor.

Assuming that all auditing has been enabled and event logs are being properly ingested, the query provided below can be used to identify potential signs of SharpSuccessor execution.

As SharpSuccessor creates a computer account, hunters can correlate SubjectLogonIDs to identify relevant events. Event ID 4741 indicates that a computer account was created, and Event ID 4662 shows that an operation was performed --- in this case, dMSA creation. Then, hunters can enrich the details of the user account that performed the action, by correlating Event ID 4624 to pull in information such as:

* Workstation name
* IP address
* Logon type

We recommend running this query on smaller time frames, given the multiple joins and alter commands leveraged.  
dataset = xdr\_data // Identify any object access/modification events for the msDS-DelegatedManagerServiceAccount object type | fields \_time, agent\_hostname, event\_type, action\_evtlog\_event\_id, action\_evtlog\_data\_fields, action\_evtlog\_message, event\_timestamp | filter event\_type = ENUM.EVENT\_LOG and action\_evtlog\_event\_id = 4662 | alter SubjectDomainName = action\_evtlog\_data\_fields -\> SubjectDomainName | alter SubjectUserSid = action\_evtlog\_data\_fields -\> SubjectUserSid | alter SubjectUserName = action\_evtlog\_data\_fields -\> SubjectUserName | alter SubjectLogonId = action\_evtlog\_data\_fields -\> SubjectLogonId | alter ObjectServer = action\_evtlog\_data\_fields -\> ObjectServer | alter ObjectType = action\_evtlog\_data\_fields -\> ObjectType | alter ObjectName = action\_evtlog\_data\_fields -\> ObjectName | alter AdditionalInfo2 = action\_evtlog\_data\_fields -\> AdditionalInfo2 | alter OperationType = action\_evtlog\_data\_fields -\> OperationType | alter AccessList = action\_evtlog\_data\_fields -\> AccessList | alter AccessMask = action\_evtlog\_data\_fields -\> AccessMask // msDS-DelegatedManagedServiceAccount Object Type | filter ObjectType = "%{0feb936f-47b3-49f2-9386-1dedc2c23765}" and AccessMask = "0x20" // Join on Event ID 4741 by SubjectLogonID to identify the machine account name that was created. | join type = inner conflict\_strategy = left ( dataset = xdr\_data | fields \_time, agent\_hostname, action\_evtlog\_event\_id, action\_evtlog\_description, event\_type, action\_evtlog\_data\_fields | filter event\_type = ENUM.EVENT\_LOG and action\_evtlog\_event\_id = 4741 // Field extraction | alter SubjectDomainName = action\_evtlog\_data\_fields -\> SubjectDomainName | alter SubjectUserSid = action\_evtlog\_data\_fields -\> SubjectUserSid | alter SubjectLogonId = action\_evtlog\_data\_fields -\> SubjectLogonId | alter SubjectUserName = action\_evtlog\_data\_fields -\> SubjectUserName | alter TargetUserName = action\_evtlog\_data\_fields -\> TargetUserName | alter TargetDomainName = action\_evtlog\_data\_fields -\> TargetDomainName | alter SamAccountName = action\_evtlog\_data\_fields -\> SamAccountName | alter DnsHostName = action\_evtlog\_data\_fields -\> DnsHostName | fields \_time as comp\_time, agent\_hostname as comp\_hostname, SubjectDomainName as comp\_SubjectDomainName, SubjectUserName as comp\_SubjectUserName, SubjectLogonId as comp\_SubjectLogonId, SubjectUserSid as comp\_SubjectUserSid, TargetUserName, SamAccountName, DnsHostName ) as cmpcreate cmpcreate.comp\_hostname = agent\_hostname and cmpcreate.comp\_SubjectUserName = SubjectUserName and cmpcreate.comp\_SubjectLogonId = SubjectLogonId and cmpcreate.comp\_SubjectUserSid = SubjectUserSid // Join on Event ID 4624 to enrich authentication activity that performed the machine account creation, and dMSA creation | join type = left ( dataset = xdr\_data | fields \_time, agent\_hostname, event\_type, action\_evtlog\_event\_id, action\_evtlog\_data\_fields | filter event\_type = ENUM.EVENT\_LOG and action\_evtlog\_event\_id = 4624 // Extract relevant fields | alter SubjectDomainName = action\_evtlog\_data\_fields -\> SubjectDomainName | alter SubjectUserSid = action\_evtlog\_data\_fields -\> SubjectUserSid | alter SubjectUserName = action\_evtlog\_data\_fields -\> SubjectUserName | alter SubjectLogonId = action\_evtlog\_data\_fields -\> SubjectLogonId | alter TargetDomainName = action\_evtlog\_data\_fields -\> TargetDomainName | alter TargetUserName = action\_evtlog\_data\_fields -\> TargetUserName | alter TargetUserSid = action\_evtlog\_data\_fields -\> TargetUserSid | alter TargetLogonId = action\_evtlog\_data\_fields -\> TargetLogonId | alter IpAddress = action\_evtlog\_data\_fields -\> IpAddress | alter IpPort = action\_evtlog\_data\_fields -\> IpPort | alter LogonType = action\_evtlog\_data\_fields -\> LogonType | alter WorkstationName = action\_evtlog\_data\_fields -\> WorkstationName | filter TargetUserName !~= "(?:(?:(?:DWM|UMFD)-\\d)|(?:NETWORK SERVICE)|(?:LOCAL SERVICE)|(?:ANONYMOUS LOGON)|(?:SYSTEM)|\\w+\\$$)" | fields agent\_hostname as auth\_hostname, TargetUserName as auth\_username, TargetLogonId as auth\_logonID, TargetUserSid as auth\_usersid, IpAddress, WorkstationName, LogonType ) as auth auth.auth\_hostname = agent\_hostname and auth.auth\_username = SubjectUserName and auth.auth\_logonID = SubjectLogonId and auth.auth\_usersid = SubjectUserSid | fields \_time, agent\_hostname, SubjectDomainName, SubjectUserSid, SubjectUserName, SubjectLogonId, OperationType, ObjectType, ObjectName, comp\_time, TargetUserName, SamAccountName, DnsHostName, LogonType, IpAddress, WorkstationName

|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 | dataset = xdr\_data // Identify any object access/modification events for the msDS-DelegatedManagerServiceAccount object type | fields \_time, agent\_hostname, event\_type, action\_evtlog\_event\_id, action\_evtlog\_data\_fields, action\_evtlog\_message, event\_timestamp | filter event\_type = ENUM.EVENT\_LOG and action\_evtlog\_event\_id = 4662 | alter SubjectDomainName = action\_evtlog\_data\_fields -\> SubjectDomainName | alter SubjectUserSid = action\_evtlog\_data\_fields -\> SubjectUserSid | alter SubjectUserName = action\_evtlog\_data\_fields -\> SubjectUserName | alter SubjectLogonId = action\_evtlog\_data\_fields -\> SubjectLogonId | alter ObjectServer = action\_evtlog\_data\_fields -\> ObjectServer | alter ObjectType = action\_evtlog\_data\_fields -\> ObjectType | alter ObjectName = action\_evtlog\_data\_fields -\> ObjectName | alter AdditionalInfo2 = action\_evtlog\_data\_fields -\> AdditionalInfo2 | alter OperationType = action\_evtlog\_data\_fields -\> OperationType | alter AccessList = action\_evtlog\_data\_fields -\> AccessList | alter AccessMask = action\_evtlog\_data\_fields -\> AccessMask // msDS-DelegatedManagedServiceAccount Object Type | filter ObjectType = "%{0feb936f-47b3-49f2-9386-1dedc2c23765}" and AccessMask = "0x20" // Join on Event ID 4741 by SubjectLogonID to identify the machine account name that was created. | join type = inner conflict\_strategy = left ( dataset = xdr\_data | fields \_time, agent\_hostname, action\_evtlog\_event\_id, action\_evtlog\_description, event\_type, action\_evtlog\_data\_fields | filter event\_type = ENUM.EVENT\_LOG and action\_evtlog\_event\_id = 4741 // Field extraction | alter SubjectDomainName = action\_evtlog\_data\_fields -\> SubjectDomainName | alter SubjectUserSid = action\_evtlog\_data\_fields -\> SubjectUserSid | alter SubjectLogonId = action\_evtlog\_data\_fields -\> SubjectLogonId | alter SubjectUserName = action\_evtlog\_data\_fields -\> SubjectUserName | alter TargetUserName = action\_evtlog\_data\_fields -\> TargetUserName | alter TargetDomainName = action\_evtlog\_data\_fields -\> TargetDomainName | alter SamAccountName = action\_evtlog\_data\_fields -\> SamAccountName | alter DnsHostName = action\_evtlog\_data\_fields -\> DnsHostName | fields \_time as comp\_time, agent\_hostname as comp\_hostname, SubjectDomainName as comp\_SubjectDomainName, SubjectUserName as comp\_SubjectUserName, SubjectLogonId as comp\_SubjectLogonId, SubjectUserSid as comp\_SubjectUserSid, TargetUserName, SamAccountName, DnsHostName ) as cmpcreate cmpcreate.comp\_hostname = agent\_hostname and cmpcreate.comp\_SubjectUserName = SubjectUserName and cmpcreate.comp\_SubjectLogonId = SubjectLogonId and cmpcreate.comp\_SubjectUserSid = SubjectUserSid // Join on Event ID 4624 to enrich authentication activity that performed the machine account creation, and dMSA creation | join type = left ( dataset = xdr\_data | fields \_time, agent\_hostname, event\_type, action\_evtlog\_event\_id, action\_evtlog\_data\_fields | filter event\_type = ENUM.EVENT\_LOG and action\_evtlog\_event\_id = 4624 // Extract relevant fields | alter SubjectDomainName = action\_evtlog\_data\_fields -\> SubjectDomainName | alter SubjectUserSid = action\_evtlog\_data\_fields -\> SubjectUserSid | alter SubjectUserName = action\_evtlog\_data\_fields -\> SubjectUserName | alter SubjectLogonId = action\_evtlog\_data\_fields -\> SubjectLogonId | alter TargetDomainName = action\_evtlog\_data\_fields -\> TargetDomainName | alter TargetUserName = action\_evtlog\_data\_fields -\> TargetUserName | alter TargetUserSid = action\_evtlog\_data\_fields -\> TargetUserSid | alter TargetLogonId = action\_evtlog\_data\_fields -\> TargetLogonId | alter IpAddress = action\_evtlog\_data\_fields -\> IpAddress | alter IpPort = action\_evtlog\_data\_fields -\> IpPort | alter LogonType = action\_evtlog\_data\_fields -\> LogonType | alter WorkstationName = action\_evtlog\_data\_fields -\> WorkstationName | filter TargetUserName !~= "(?:(?:(?:DWM|UMFD)-\\d)|(?:NETWORK SERVICE)|(?:LOCAL SERVICE)|(?:ANONYMOUS LOGON)|(?:SYSTEM)|\\w+\\$$)" | fields agent\_hostname as auth\_hostname, TargetUserName as auth\_username, TargetLogonId as auth\_logonID, TargetUserSid as auth\_usersid, IpAddress, WorkstationName, LogonType ) as auth auth.auth\_hostname = agent\_hostname and auth.auth\_username = SubjectUserName and auth.auth\_logonID = SubjectLogonId and auth.auth\_usersid = SubjectUserSid | fields \_time, agent\_hostname, SubjectDomainName, SubjectUserSid, SubjectUserName, SubjectLogonId, OperationType, ObjectType, ObjectName, comp\_time, TargetUserName, SamAccountName, DnsHostName, LogonType, IpAddress, WorkstationName |

For customers who have enabled auditing and are ingesting Event ID 5136, the following query can be used to identify creation of dMSAs.  
// Description: Identify creation of a dMSA dataset = xdr\_data | fields \_time, agent\_hostname, event\_type, action\_evtlog\_event\_id, action\_evtlog\_data\_fields | filter event\_type = ENUM.EVENT\_LOG and action\_evtlog\_event\_id = 5136 | alter SubjectDomainName = action\_evtlog\_data\_fields -\> SubjectDomainName | alter SubjectLogonId = action\_evtlog\_data\_fields -\> SubjectLogonId | alter SubjectUserName = action\_evtlog\_data\_fields -\> SubjectUserName | alter SubjectUserSid = action\_evtlog\_data\_fields -\> SubjectUserSid | alter AppCorrelationID = action\_evtlog\_data\_fields -\> AppCorrelationID | alter AttributeLDAPDisplayName = action\_evtlog\_data\_fields -\> AttributeLDAPDisplayName | alter AttributeSyntaxOID = action\_evtlog\_data\_fields -\> AttributeSyntaxOID | alter AttributeValue = action\_evtlog\_data\_fields -\> AttributeValue | alter DSName = action\_evtlog\_data\_fields -\> DSName | alter DSType = action\_evtlog\_data\_fields -\> DSType | alter ObjectClass = action\_evtlog\_data\_fields -\> ObjectClass | alter ObjectDN = action\_evtlog\_data\_fields -\> ObjectDN | alter ObjectGUID = action\_evtlog\_data\_fields -\> ObjectGUID | alter OpCorrelationID = action\_evtlog\_data\_fields -\> OpCorrelationID | alter OperationType = action\_evtlog\_data\_fields -\> OperationType // ObjectGUID is the MsDS-DelegatedManagedServiceAccount and the attribute value of 2 where the operation is a Value Add | filter ObjectClass = "msDS-DelegatedManagedServiceAccount" and AttributeLDAPDisplayName = "msDS-DelegatedMSAState" and AttributeValue = "2" and OperationType = "%%14674" // Query to pull in the authentication activity that performed the object access/modification | join type = left ( dataset = xdr\_data | fields \_time, agent\_hostname, event\_type, action\_evtlog\_event\_id, action\_evtlog\_data\_fields | filter event\_type = ENUM.EVENT\_LOG and action\_evtlog\_event\_id = 4624 // Extract relevant fields | alter SubjectDomainName = action\_evtlog\_data\_fields -\> SubjectDomainName | alter SubjectUserSid = action\_evtlog\_data\_fields -\> SubjectUserSid | alter SubjectUserName = action\_evtlog\_data\_fields -\> SubjectUserName | alter SubjectLogonId = action\_evtlog\_data\_fields -\> SubjectLogonId | alter TargetDomainName = action\_evtlog\_data\_fields -\> TargetDomainName | alter TargetUserName = action\_evtlog\_data\_fields -\> TargetUserName | alter TargetUserSid = action\_evtlog\_data\_fields -\> TargetUserSid | alter TargetLogonId = action\_evtlog\_data\_fields -\> TargetLogonId | alter IpAddress = action\_evtlog\_data\_fields -\> IpAddress | alter IpPort = action\_evtlog\_data\_fields -\> IpPort | alter LogonType = action\_evtlog\_data\_fields -\> LogonType | alter WorkstationName = action\_evtlog\_data\_fields -\> WorkstationName | filter TargetUserName !~= "(?:(?:(?:DWM|UMFD)-\\d)|(?:NETWORK SERVICE)|(?:LOCAL SERVICE)|(?:ANONYMOUS LOGON)|(?:SYSTEM)|\\w+\\$$)" | fields agent\_hostname as auth\_hostname, TargetUserName as auth\_username, TargetLogonId as auth\_logonID, TargetUserSid as auth\_usersid, IpAddress, WorkstationName, LogonType ) as auth auth.auth\_hostname = agent\_hostname and auth.auth\_username = SubjectUserName and auth.auth\_logonID = SubjectLogonId and auth.auth\_usersid = SubjectUserSid | fields \_time, agent\_hostname, SubjectDomainName, SubjectUserName, SubjectUserSid, SubjectLogonId, ObjectDN, ObjectGUID, AttributeLDAPDisplayName, AttributeValue, LogonType, IpAddress, WorkstationName

|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 | // Description: Identify creation of a dMSA dataset = xdr\_data | fields \_time, agent\_hostname, event\_type, action\_evtlog\_event\_id, action\_evtlog\_data\_fields | filter event\_type = ENUM.EVENT\_LOG and action\_evtlog\_event\_id = 5136 | alter SubjectDomainName = action\_evtlog\_data\_fields -\> SubjectDomainName | alter SubjectLogonId = action\_evtlog\_data\_fields -\> SubjectLogonId | alter SubjectUserName = action\_evtlog\_data\_fields -\> SubjectUserName | alter SubjectUserSid = action\_evtlog\_data\_fields -\> SubjectUserSid | alter AppCorrelationID = action\_evtlog\_data\_fields -\> AppCorrelationID | alter AttributeLDAPDisplayName = action\_evtlog\_data\_fields -\> AttributeLDAPDisplayName | alter AttributeSyntaxOID = action\_evtlog\_data\_fields -\> AttributeSyntaxOID | alter AttributeValue = action\_evtlog\_data\_fields -\> AttributeValue | alter DSName = action\_evtlog\_data\_fields -\> DSName | alter DSType = action\_evtlog\_data\_fields -\> DSType | alter ObjectClass = action\_evtlog\_data\_fields -\> ObjectClass | alter ObjectDN = action\_evtlog\_data\_fields -\> ObjectDN | alter ObjectGUID = action\_evtlog\_data\_fields -\> ObjectGUID | alter OpCorrelationID = action\_evtlog\_data\_fields -\> OpCorrelationID | alter OperationType = action\_evtlog\_data\_fields -\> OperationType // ObjectGUID is the MsDS-DelegatedManagedServiceAccount and the attribute value of 2 where the operation is a Value Add | filter ObjectClass = "msDS-DelegatedManagedServiceAccount" and AttributeLDAPDisplayName = "msDS-DelegatedMSAState" and AttributeValue = "2" and OperationType = "%%14674" // Query to pull in the authentication activity that performed the object access/modification | join type = left ( dataset = xdr\_data | fields \_time, agent\_hostname, event\_type, action\_evtlog\_event\_id, action\_evtlog\_data\_fields | filter event\_type = ENUM.EVENT\_LOG and action\_evtlog\_event\_id = 4624 // Extract relevant fields | alter SubjectDomainName = action\_evtlog\_data\_fields -\> SubjectDomainName | alter SubjectUserSid = action\_evtlog\_data\_fields -\> SubjectUserSid | alter SubjectUserName = action\_evtlog\_data\_fields -\> SubjectUserName | alter SubjectLogonId = action\_evtlog\_data\_fields -\> SubjectLogonId | alter TargetDomainName = action\_evtlog\_data\_fields -\> TargetDomainName | alter TargetUserName = action\_evtlog\_data\_fields -\> TargetUserName | alter TargetUserSid = action\_evtlog\_data\_fields -\> TargetUserSid | alter TargetLogonId = action\_evtlog\_data\_fields -\> TargetLogonId | alter IpAddress = action\_evtlog\_data\_fields -\> IpAddress | alter IpPort = action\_evtlog\_data\_fields -\> IpPort | alter LogonType = action\_evtlog\_data\_fields -\> LogonType | alter WorkstationName = action\_evtlog\_data\_fields -\> WorkstationName | filter TargetUserName !~= "(?:(?:(?:DWM|UMFD)-\\d)|(?:NETWORK SERVICE)|(?:LOCAL SERVICE)|(?:ANONYMOUS LOGON)|(?:SYSTEM)|\\w+\\$$)" | fields agent\_hostname as auth\_hostname, TargetUserName as auth\_username, TargetLogonId as auth\_logonID, TargetUserSid as auth\_usersid, IpAddress, WorkstationName, LogonType ) as auth auth.auth\_hostname = agent\_hostname and auth.auth\_username = SubjectUserName and auth.auth\_logonID = SubjectLogonId and auth.auth\_usersid = SubjectUserSid | fields \_time, agent\_hostname, SubjectDomainName, SubjectUserName, SubjectUserSid, SubjectLogonId, ObjectDN, ObjectGUID, AttributeLDAPDisplayName, AttributeValue, LogonType, IpAddress, WorkstationName |

Additionally, the following query can be used to identify which gMSA or standalone Managed Service Account (sMSA) account the new dMSA should supersede:  
// Description: Identify which gMSA/sMSA account the new dMSA should supersede dataset = xdr\_data | fields \_time, agent\_hostname, event\_type, action\_evtlog\_event\_id, action\_evtlog\_data\_fields | filter event\_type = ENUM.EVENT\_LOG and action\_evtlog\_event\_id = 5136 | alter SubjectDomainName = action\_evtlog\_data\_fields -\> SubjectDomainName | alter SubjectLogonId = action\_evtlog\_data\_fields -\> SubjectLogonId | alter SubjectUserName = action\_evtlog\_data\_fields -\> SubjectUserName | alter SubjectUserSid = action\_evtlog\_data\_fields -\> SubjectUserSid | alter AppCorrelationID = action\_evtlog\_data\_fields -\> AppCorrelationID | alter AttributeLDAPDisplayName = action\_evtlog\_data\_fields -\> AttributeLDAPDisplayName | alter AttributeSyntaxOID = action\_evtlog\_data\_fields -\> AttributeSyntaxOID | alter AttributeValue = action\_evtlog\_data\_fields -\> AttributeValue | alter DSName = action\_evtlog\_data\_fields -\> DSName | alter DSType = action\_evtlog\_data\_fields -\> DSType | alter ObjectClass = action\_evtlog\_data\_fields -\> ObjectClass | alter ObjectDN = action\_evtlog\_data\_fields -\> ObjectDN | alter ObjectGUID = action\_evtlog\_data\_fields -\> ObjectGUID | alter OpCorrelationID = action\_evtlog\_data\_fields -\> OpCorrelationID | alter OperationType = action\_evtlog\_data\_fields -\> OperationType // ObjectGUID is the MsDS-DelegatedManagedServiceAccount and the AttributeLDAPDisplayName is msDS-ManagedAccountPrecededByLink where a value was added | filter ObjectClass = "msDS-DelegatedManagedServiceAccount" and AttributeLDAPDisplayName = "msDS-ManagedAccountPrecededByLink" and OperationType = "%%14674" // Query to pull in the authentication activity that performed the object access/modification | join type = left ( dataset = xdr\_data | fields \_time, agent\_hostname, event\_type, action\_evtlog\_event\_id, action\_evtlog\_data\_fields | filter event\_type = ENUM.EVENT\_LOG and action\_evtlog\_event\_id = 4624 // Extract relevant fields | alter SubjectDomainName = action\_evtlog\_data\_fields -\> SubjectDomainName | alter SubjectUserSid = action\_evtlog\_data\_fields -\> SubjectUserSid | alter SubjectUserName = action\_evtlog\_data\_fields -\> SubjectUserName | alter SubjectLogonId = action\_evtlog\_data\_fields -\> SubjectLogonId | alter TargetDomainName = action\_evtlog\_data\_fields -\> TargetDomainName | alter TargetUserName = action\_evtlog\_data\_fields -\> TargetUserName | alter TargetUserSid = action\_evtlog\_data\_fields -\> TargetUserSid | alter TargetLogonId = action\_evtlog\_data\_fields -\> TargetLogonId | alter IpAddress = action\_evtlog\_data\_fields -\> IpAddress | alter IpPort = action\_evtlog\_data\_fields -\> IpPort | alter LogonType = action\_evtlog\_data\_fields -\> LogonType | alter WorkstationName = action\_evtlog\_data\_fields -\> WorkstationName | filter TargetUserName !~= "(?:(?:(?:DWM|UMFD)-\\d)|(?:NETWORK SERVICE)|(?:LOCAL SERVICE)|(?:ANONYMOUS LOGON)|(?:SYSTEM)|\\w+\\$$)" | fields agent\_hostname as auth\_hostname, TargetUserName as auth\_username, TargetLogonId as auth\_logonID, TargetUserSid as auth\_usersid, IpAddress, WorkstationName, LogonType ) as auth auth.auth\_hostname = agent\_hostname and auth.auth\_username = SubjectUserName and auth.auth\_logonID = SubjectLogonId and auth.auth\_usersid = SubjectUserSid | fields \_time, agent\_hostname, SubjectDomainName, SubjectUserName, SubjectUserSid, SubjectLogonId, ObjectDN, ObjectGUID, AttributeLDAPDisplayName, AttributeValue, LogonType, IpAddress, WorkstationName

|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 | // Description: Identify which gMSA/sMSA account the new dMSA should supersede dataset = xdr\_data | fields \_time, agent\_hostname, event\_type, action\_evtlog\_event\_id, action\_evtlog\_data\_fields | filter event\_type = ENUM.EVENT\_LOG and action\_evtlog\_event\_id = 5136 | alter SubjectDomainName = action\_evtlog\_data\_fields -\> SubjectDomainName | alter SubjectLogonId = action\_evtlog\_data\_fields -\> SubjectLogonId | alter SubjectUserName = action\_evtlog\_data\_fields -\> SubjectUserName | alter SubjectUserSid = action\_evtlog\_data\_fields -\> SubjectUserSid | alter AppCorrelationID = action\_evtlog\_data\_fields -\> AppCorrelationID | alter AttributeLDAPDisplayName = action\_evtlog\_data\_fields -\> AttributeLDAPDisplayName | alter AttributeSyntaxOID = action\_evtlog\_data\_fields -\> AttributeSyntaxOID | alter AttributeValue = action\_evtlog\_data\_fields -\> AttributeValue | alter DSName = action\_evtlog\_data\_fields -\> DSName | alter DSType = action\_evtlog\_data\_fields -\> DSType | alter ObjectClass = action\_evtlog\_data\_fields -\> ObjectClass | alter ObjectDN = action\_evtlog\_data\_fields -\> ObjectDN | alter ObjectGUID = action\_evtlog\_data\_fields -\> ObjectGUID | alter OpCorrelationID = action\_evtlog\_data\_fields -\> OpCorrelationID | alter OperationType = action\_evtlog\_data\_fields -\> OperationType // ObjectGUID is the MsDS-DelegatedManagedServiceAccount and the AttributeLDAPDisplayName is msDS-ManagedAccountPrecededByLink where a value was added | filter ObjectClass = "msDS-DelegatedManagedServiceAccount" and AttributeLDAPDisplayName = "msDS-ManagedAccountPrecededByLink" and OperationType = "%%14674" // Query to pull in the authentication activity that performed the object access/modification | join type = left ( dataset = xdr\_data | fields \_time, agent\_hostname, event\_type, action\_evtlog\_event\_id, action\_evtlog\_data\_fields | filter event\_type = ENUM.EVENT\_LOG and action\_evtlog\_event\_id = 4624 // Extract relevant fields | alter SubjectDomainName = action\_evtlog\_data\_fields -\> SubjectDomainName | alter SubjectUserSid = action\_evtlog\_data\_fields -\> SubjectUserSid | alter SubjectUserName = action\_evtlog\_data\_fields -\> SubjectUserName | alter SubjectLogonId = action\_evtlog\_data\_fields -\> SubjectLogonId | alter TargetDomainName = action\_evtlog\_data\_fields -\> TargetDomainName | alter TargetUserName = action\_evtlog\_data\_fields -\> TargetUserName | alter TargetUserSid = action\_evtlog\_data\_fields -\> TargetUserSid | alter TargetLogonId = action\_evtlog\_data\_fields -\> TargetLogonId | alter IpAddress = action\_evtlog\_data\_fields -\> IpAddress | alter IpPort = action\_evtlog\_data\_fields -\> IpPort | alter LogonType = action\_evtlog\_data\_fields -\> LogonType | alter WorkstationName = action\_evtlog\_data\_fields -\> WorkstationName | filter TargetUserName !~= "(?:(?:(?:DWM|UMFD)-\\d)|(?:NETWORK SERVICE)|(?:LOCAL SERVICE)|(?:ANONYMOUS LOGON)|(?:SYSTEM)|\\w+\\$$)" | fields agent\_hostname as auth\_hostname, TargetUserName as auth\_username, TargetLogonId as auth\_logonID, TargetUserSid as auth\_usersid, IpAddress, WorkstationName, LogonType ) as auth auth.auth\_hostname = agent\_hostname and auth.auth\_username = SubjectUserName and auth.auth\_logonID = SubjectLogonId and auth.auth\_usersid = SubjectUserSid | fields \_time, agent\_hostname, SubjectDomainName, SubjectUserName, SubjectUserSid, SubjectLogonId, ObjectDN, ObjectGUID, AttributeLDAPDisplayName, AttributeValue, LogonType, IpAddress, WorkstationName |

The following queries can be used independently. Alternatively, they can be combined in a single query that will show details of the new dMSA, the new account name and the superseded accounts.  
// Description: Identify creation of dMSA dataset = xdr\_data | fields \_time, agent\_hostname, event\_type, action\_evtlog\_event\_id, action\_evtlog\_data\_fields | filter event\_type = ENUM.EVENT\_LOG and action\_evtlog\_event\_id = 5136 | alter SubjectDomainName = action\_evtlog\_data\_fields -\> SubjectDomainName | alter SubjectLogonId = action\_evtlog\_data\_fields -\> SubjectLogonId | alter SubjectUserName = action\_evtlog\_data\_fields -\> SubjectUserName | alter SubjectUserSid = action\_evtlog\_data\_fields -\> SubjectUserSid | alter AppCorrelationID = action\_evtlog\_data\_fields -\> AppCorrelationID | alter AttributeLDAPDisplayName = action\_evtlog\_data\_fields -\> AttributeLDAPDisplayName | alter AttributeSyntaxOID = action\_evtlog\_data\_fields -\> AttributeSyntaxOID | alter AttributeValue = action\_evtlog\_data\_fields -\> AttributeValue | alter DSName = action\_evtlog\_data\_fields -\> DSName | alter DSType = action\_evtlog\_data\_fields -\> DSType | alter ObjectClass = action\_evtlog\_data\_fields -\> ObjectClass | alter ObjectDN = action\_evtlog\_data\_fields -\> ObjectDN | alter ObjectGUID = action\_evtlog\_data\_fields -\> ObjectGUID | alter OpCorrelationID = action\_evtlog\_data\_fields -\> OpCorrelationID | alter OperationType = action\_evtlog\_data\_fields -\> OperationType // ObjectGUID is the MsDS-DelegatedManagedServiceAccount and the attribute value of 2 where the operation is a Value Add | filter ObjectClass = "msDS-DelegatedManagedServiceAccount" and AttributeLDAPDisplayName = "msDS-DelegatedMSAState" and AttributeValue = "2" and OperationType = "%%14674" // Attempt to join on a 5136 event where the dMSA that was created shows the value of the superseded sMSA/gMSA account | join type = left ( // Description: Identify which gMSA/sMSA account the new dMSA should supersede dataset = xdr\_data | fields \_time, agent\_hostname, event\_type, action\_evtlog\_event\_id, action\_evtlog\_data\_fields | filter event\_type = ENUM.EVENT\_LOG and action\_evtlog\_event\_id = 5136 | alter SubjectDomainName = action\_evtlog\_data\_fields -\> SubjectDomainName | alter SubjectLogonId = action\_evtlog\_data\_fields -\> SubjectLogonId | alter SubjectUserName = action\_evtlog\_data\_fields -\> SubjectUserName | alter SubjectUserSid = action\_evtlog\_data\_fields -\> SubjectUserSid | alter AttributeLDAPDisplayName = action\_evtlog\_data\_fields -\> AttributeLDAPDisplayName | alter AttributeValue = action\_evtlog\_data\_fields -\> AttributeValue | alter ObjectClass = action\_evtlog\_data\_fields -\> ObjectClass | alter ObjectDN = action\_evtlog\_data\_fields -\> ObjectDN | alter ObjectGUID = action\_evtlog\_data\_fields -\> ObjectGUID | alter OperationType = action\_evtlog\_data\_fields -\> OperationType // ObjectGUID is the MsDS-DelegatedManagedServiceAccount and the AttributeLDAPDisplayName is msDS-ManagedAccountPrecededByLink where a value was added | filter ObjectClass = "msDS-DelegatedManagedServiceAccount" and AttributeLDAPDisplayName = "msDS-ManagedAccountPrecededByLink" and OperationType = "%%14674" | fields SubjectDomainName, SubjectLogonId, SubjectUserName, SubjectUserSid, AttributeValue as SupersededAttributeValue, ObjectGUID, AttributeLDAPDisplayName as supersededAttributeLDAPDisplayName ) as superseded superseded.SubjectDomainName = SubjectDomainName and superseded.SubjectUserName = SubjectUserName and superseded.ObjectGUID = ObjectGUID and superseded.SubjectLogonId = SubjectLogonId and superseded.SubjectUserSid = SubjectUserSid // Query to pull in the authentication activity that performed the object access/modification | join type = left ( dataset = xdr\_data | fields \_time, agent\_hostname, event\_type, action\_evtlog\_event\_id, action\_evtlog\_data\_fields | filter event\_type = ENUM.EVENT\_LOG and action\_evtlog\_event\_id = 4624 // Extract relevant fields | alter SubjectDomainName = action\_evtlog\_data\_fields -\> SubjectDomainName | alter SubjectUserSid = action\_evtlog\_data\_fields -\> SubjectUserSid | alter SubjectUserName = action\_evtlog\_data\_fields -\> SubjectUserName | alter SubjectLogonId = action\_evtlog\_data\_fields -\> SubjectLogonId | alter TargetDomainName = action\_evtlog\_data\_fields -\> TargetDomainName | alter TargetUserName = action\_evtlog\_data\_fields -\> TargetUserName | alter TargetUserSid = action\_evtlog\_data\_fields -\> TargetUserSid | alter TargetLogonId = action\_evtlog\_data\_fields -\> TargetLogonId | alter IpAddress = action\_evtlog\_data\_fields -\> IpAddress | alter IpPort = action\_evtlog\_data\_fields -\> IpPort | alter LogonType = action\_evtlog\_data\_fields -\> LogonType | alter WorkstationName = action\_evtlog\_data\_fields -\> WorkstationName | filter TargetUserName !~= "(?:(?:(?:DWM|UMFD)-\\d)|(?:NETWORK SERVICE)|(?:LOCAL SERVICE)|(?:ANONYMOUS LOGON)|(?:SYSTEM)|\\w+\\$$)" | fields agent\_hostname as auth\_hostname, TargetUserName as auth\_username, TargetLogonId as auth\_logonID, TargetUserSid as auth\_usersid, IpAddress, WorkstationName, LogonType ) as auth auth.auth\_hostname = agent\_hostname and auth.auth\_username = SubjectUserName and auth.auth\_logonID = SubjectLogonId and auth.auth\_usersid = SubjectUserSid | fields \_time, agent\_hostname, SubjectDomainName, SubjectUserName, SubjectUserSid, SubjectLogonId, ObjectDN, ObjectGUID, AttributeLDAPDisplayName, AttributeValue, SupersededAttributeValue, SupersededAttributeValue, LogonType, IpAddress, WorkstationName

|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 | // Description: Identify creation of dMSA dataset = xdr\_data | fields \_time, agent\_hostname, event\_type, action\_evtlog\_event\_id, action\_evtlog\_data\_fields | filter event\_type = ENUM.EVENT\_LOG and action\_evtlog\_event\_id = 5136 | alter SubjectDomainName = action\_evtlog\_data\_fields -\> SubjectDomainName | alter SubjectLogonId = action\_evtlog\_data\_fields -\> SubjectLogonId | alter SubjectUserName = action\_evtlog\_data\_fields -\> SubjectUserName | alter SubjectUserSid = action\_evtlog\_data\_fields -\> SubjectUserSid | alter AppCorrelationID = action\_evtlog\_data\_fields -\> AppCorrelationID | alter AttributeLDAPDisplayName = action\_evtlog\_data\_fields -\> AttributeLDAPDisplayName | alter AttributeSyntaxOID = action\_evtlog\_data\_fields -\> AttributeSyntaxOID | alter AttributeValue = action\_evtlog\_data\_fields -\> AttributeValue | alter DSName = action\_evtlog\_data\_fields -\> DSName | alter DSType = action\_evtlog\_data\_fields -\> DSType | alter ObjectClass = action\_evtlog\_data\_fields -\> ObjectClass | alter ObjectDN = action\_evtlog\_data\_fields -\> ObjectDN | alter ObjectGUID = action\_evtlog\_data\_fields -\> ObjectGUID | alter OpCorrelationID = action\_evtlog\_data\_fields -\> OpCorrelationID | alter OperationType = action\_evtlog\_data\_fields -\> OperationType // ObjectGUID is the MsDS-DelegatedManagedServiceAccount and the attribute value of 2 where the operation is a Value Add | filter ObjectClass = "msDS-DelegatedManagedServiceAccount" and AttributeLDAPDisplayName = "msDS-DelegatedMSAState" and AttributeValue = "2" and OperationType = "%%14674" // Attempt to join on a 5136 event where the dMSA that was created shows the value of the superseded sMSA/gMSA account | join type = left ( // Description: Identify which gMSA/sMSA account the new dMSA should supersede dataset = xdr\_data | fields \_time, agent\_hostname, event\_type, action\_evtlog\_event\_id, action\_evtlog\_data\_fields | filter event\_type = ENUM.EVENT\_LOG and action\_evtlog\_event\_id = 5136 | alter SubjectDomainName = action\_evtlog\_data\_fields -\> SubjectDomainName | alter SubjectLogonId = action\_evtlog\_data\_fields -\> SubjectLogonId | alter SubjectUserName = action\_evtlog\_data\_fields -\> SubjectUserName | alter SubjectUserSid = action\_evtlog\_data\_fields -\> SubjectUserSid | alter AttributeLDAPDisplayName = action\_evtlog\_data\_fields -\> AttributeLDAPDisplayName | alter AttributeValue = action\_evtlog\_data\_fields -\> AttributeValue | alter ObjectClass = action\_evtlog\_data\_fields -\> ObjectClass | alter ObjectDN = action\_evtlog\_data\_fields -\> ObjectDN | alter ObjectGUID = action\_evtlog\_data\_fields -\> ObjectGUID | alter OperationType = action\_evtlog\_data\_fields -\> OperationType // ObjectGUID is the MsDS-DelegatedManagedServiceAccount and the AttributeLDAPDisplayName is msDS-ManagedAccountPrecededByLink where a value was added | filter ObjectClass = "msDS-DelegatedManagedServiceAccount" and AttributeLDAPDisplayName = "msDS-ManagedAccountPrecededByLink" and OperationType = "%%14674" | fields SubjectDomainName, SubjectLogonId, SubjectUserName, SubjectUserSid, AttributeValue as SupersededAttributeValue, ObjectGUID, AttributeLDAPDisplayName as supersededAttributeLDAPDisplayName ) as superseded superseded.SubjectDomainName = SubjectDomainName and superseded.SubjectUserName = SubjectUserName and superseded.ObjectGUID = ObjectGUID and superseded.SubjectLogonId = SubjectLogonId and superseded.SubjectUserSid = SubjectUserSid // Query to pull in the authentication activity that performed the object access/modification | join type = left ( dataset = xdr\_data | fields \_time, agent\_hostname, event\_type, action\_evtlog\_event\_id, action\_evtlog\_data\_fields | filter event\_type = ENUM.EVENT\_LOG and action\_evtlog\_event\_id = 4624 // Extract relevant fields | alter SubjectDomainName = action\_evtlog\_data\_fields -\> SubjectDomainName | alter SubjectUserSid = action\_evtlog\_data\_fields -\> SubjectUserSid | alter SubjectUserName = action\_evtlog\_data\_fields -\> SubjectUserName | alter SubjectLogonId = action\_evtlog\_data\_fields -\> SubjectLogonId | alter TargetDomainName = action\_evtlog\_data\_fields -\> TargetDomainName | alter TargetUserName = action\_evtlog\_data\_fields -\> TargetUserName | alter TargetUserSid = action\_evtlog\_data\_fields -\> TargetUserSid | alter TargetLogonId = action\_evtlog\_data\_fields -\> TargetLogonId | alter IpAddress = action\_evtlog\_data\_fields -\> IpAddress | alter IpPort = action\_evtlog\_data\_fields -\> IpPort | alter LogonType = action\_evtlog\_data\_fields -\> LogonType | alter WorkstationName = action\_evtlog\_data\_fields -\> WorkstationName | filter TargetUserName !~= "(?:(?:(?:DWM|UMFD)-\\d)|(?:NETWORK SERVICE)|(?:LOCAL SERVICE)|(?:ANONYMOUS LOGON)|(?:SYSTEM)|\\w+\\$$)" | fields agent\_hostname as auth\_hostname, TargetUserName as auth\_username, TargetLogonId as auth\_logonID, TargetUserSid as auth\_usersid, IpAddress, WorkstationName, LogonType ) as auth auth.auth\_hostname = agent\_hostname and auth.auth\_username = SubjectUserName and auth.auth\_logonID = SubjectLogonId and auth.auth\_usersid = SubjectUserSid | fields \_time, agent\_hostname, SubjectDomainName, SubjectUserName, SubjectUserSid, SubjectLogonId, ObjectDN, ObjectGUID, AttributeLDAPDisplayName, AttributeValue, SupersededAttributeValue, SupersededAttributeValue, LogonType, IpAddress, WorkstationName |

### XDR Alerts and MITRE Techniques

Table 1 lists the Cortex XDR alerts and the associated MITRE ATT\&CK techniques these alerts detect.

|-----------------------------------------------------------|----------------------------------------|----------------------------------------------------------------------------|
| **Alert Name**                                            | **Alert Source**                       | **ATT\&CK Technique**                                                      |
| Possible Privilege Escalation using Delegated MSA account | XDR Analytics, Identity Analytics      | [Account Manipulation (T1098)](https://attack.mitre.org/techniques/T1098/) |
| Rare machine account creation                             | XDR Analytics BIOC, Identity Analytics | [Create Account (T1136)](https://attack.mitre.org/techniques/T1136)        |

Table 1. Relevant alerts and MITRE techniques.
Back to top

### Tags

* [Active Directory](https://unit42.paloaltonetworks.com/tag/active-directory/ "Active Directory")
* [Microsoft](https://unit42.paloaltonetworks.com/tag/microsoft/ "Microsoft")
* [PowerShell](https://unit42.paloaltonetworks.com/tag/powershell/ "PowerShell")  
  [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research") [Next: Project AK47: Uncovering a Link to the SharePoint Vulnerability Attacks](https://unit42.paloaltonetworks.com/ak47-activity-linked-to-sharepoint-vulnerabilities/ "Project AK47: Uncovering a Link to the SharePoint Vulnerability Attacks")

### Table of Contents

* 

### Related Articles

* [Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams](https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/ "article - table of contents")
* [How We Added WebAuthn to a Browser-Based RDP Client](https://unit42.paloaltonetworks.com/webauthn-added-to-browser-based-rdp/ "article - table of contents")
* [Inside AD CS Escalation: Unpacking Advanced Misuse Techniques and Tools](https://unit42.paloaltonetworks.com/active-directory-certificate-services-exploitation/ "article - table of contents")

## Related Vulnerabilities Resources

![Pictorial representation of a group of people interacting with a dynamic 3D holographic display of colorful, undulating data waves on a table.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/09/11_Myth-Busting_Overview_1920x900-786x368.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/Insights-icon-white.svg)Insights](https://unit42.paloaltonetworks.com/category/insights/) August 4, 2026 [#### The Frontier AI Vulnerability Burst: Industrializing Autonomous Zero-Day Discovery in Open-Source Software](https://unit42.paloaltonetworks.com/frontier-ai-vulnerability-burst/)

* [AI](https://unit42.paloaltonetworks.com/tag/ai/ "AI")

* [Frontier AI](https://unit42.paloaltonetworks.com/tag/frontier-ai/ "Frontier AI")

* [Vulnerability Exploitation](https://unit42.paloaltonetworks.com/tag/vulnerability-exploitation/ "Vulnerability Exploitation")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/frontier-ai-vulnerability-burst/ "The Frontier AI Vulnerability Burst: Industrializing Autonomous Zero-Day Discovery in Open-Source Software")  
  ![Pictorial representation of AI-enabled autonomous cyberattacks. A digital illustration depicting abstract, interconnected data streams in vibrant colors on a dark blue background](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/07/AdobeStock_992950050-3-782x440.jpeg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) July 30, 2026 [#### Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks](https://unit42.paloaltonetworks.com/autonomous-ai-cyber-attack-campaign/)

* [ChatGPT](https://unit42.paloaltonetworks.com/tag/chatgpt/ "ChatGPT")

* [Claude code](https://unit42.paloaltonetworks.com/tag/claude-code/ "Claude code")

* [CVEs](https://unit42.paloaltonetworks.com/tag/cves/ "CVEs")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/autonomous-ai-cyber-attack-campaign/ "Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks")  
  ![Pictorial representation of three zero-day vulnerabilities in Siemens ROX II OT switches. Digital illustration of a global network featuring interconnected lines and nodes over a map of the world, highlighted with neon lights and digital elements.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/07/03_Vulnerabilities_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) July 17, 2026 [#### Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy](https://unit42.paloaltonetworks.com/siemens-rox-ii-zero-day-vulnerabilities/)

* [Command injection](https://unit42.paloaltonetworks.com/tag/command-injection/ "Command injection")

* [CVE-2025-40947](https://unit42.paloaltonetworks.com/tag/cve-2025-40947/ "CVE-2025-40947")

* [CVE-2025-40948](https://unit42.paloaltonetworks.com/tag/cve-2025-40948/ "CVE-2025-40948")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/siemens-rox-ii-zero-day-vulnerabilities/ "Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy")  
  ![Pictorial representation of PAN-OS CVE-2026-0257. A vibrant city skyline at night, with tall skyscrapers and glowing digital beams extending into the sky, suggesting advanced technology and connectivity.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/06/07_Vulnerabilities_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) June 9, 2026 [#### Threat Brief: Active Exploitation of PAN-OS CVE-2026-0257](https://unit42.paloaltonetworks.com/active-exploitation-of-pan-os-cve-2026-0257/)

* [CVE-2026-0257](https://unit42.paloaltonetworks.com/tag/cve-2026-0257/ "CVE-2026-0257")

* [Vulnerability](https://unit42.paloaltonetworks.com/tag/vulnerability/ "vulnerability")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/active-exploitation-of-pan-os-cve-2026-0257/ "Threat Brief: Active Exploitation of PAN-OS CVE-2026-0257")  
  ![Pictorial representation of CVE-2026-30300. Digital illustration of a map of North America with interconnected glowing lines and dots symbolizing network connections across the continent.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/05/06_Vulnerabilities_1920x900-3-1-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) May 6, 2026 [#### Threat Brief: Exploitation of PAN-OS Captive Portal Zero-Day for Unauthenticated Remote Code Execution](https://unit42.paloaltonetworks.com/captive-portal-zero-day/)

* [CVE-2026-0300](https://unit42.paloaltonetworks.com/tag/cve-2026-0300/ "CVE-2026-0300")

* [EarthWorm](https://unit42.paloaltonetworks.com/tag/earthworm/ "EarthWorm")

* [PAN-OS](https://unit42.paloaltonetworks.com/tag/pan-os/ "PAN-OS")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/captive-portal-zero-day/ "Threat Brief: Exploitation of PAN-OS Captive Portal Zero-Day for Unauthenticated Remote Code Execution")  
  ![Pictorial representation of a severe Linux vulnerability. Close-up of a woman wearing glasses and focusing intently on a computer screen.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/05/05_Vulnerabilities_1920x900-2-1-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) May 5, 2026 [#### Copy Fail: What You Need to Know About the Most Severe Linux Threat in Years](https://unit42.paloaltonetworks.com/cve-2026-31431-copy-fail/)

* [Containers](https://unit42.paloaltonetworks.com/tag/containers/ "Containers")

* [CVE-2026-31431](https://unit42.paloaltonetworks.com/tag/cve-2026-31431/ "CVE-2026-31431")

* [Kubernetes](https://unit42.paloaltonetworks.com/tag/kubernetes/ "Kubernetes")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/cve-2026-31431-copy-fail/ "Copy Fail: What You Need to Know About the Most Severe Linux Threat in Years")  
  ![Pictorial representation of CVE-2023-33538. Abstract image of a glowing red Wi-Fi symbol on a circuit board, with intricate patterns and a futuristic appearance.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/04/04_Vulnerabilities_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) April 16, 2026 [#### A Deep Dive Into Attempted Exploitation of CVE-2023-33538](https://unit42.paloaltonetworks.com/exploitation-of-cve-2023-33538/)

* [Botnet](https://unit42.paloaltonetworks.com/tag/botnet/ "botnet")

* [Command injection](https://unit42.paloaltonetworks.com/tag/command-injection/ "Command injection")

* [CVE-2023-33538](https://unit42.paloaltonetworks.com/tag/cve-2023-33538/ "CVE-2023-33538")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/exploitation-of-cve-2023-33538/ "A Deep Dive Into Attempted Exploitation of CVE-2023-33538")  
  ![Pictorial representation of BeyondTrust vulnerability CVE-2026-1731. Digital art depicting a stylized mountain range with vibrant blue and red hues. The peaks are accentuated by glowing particles and an abstract, starry backdrop, creating a futuristic landscape.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/02/14_Overview_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) February 19, 2026 [#### VShell and SparkRAT Observed in Exploitation of BeyondTrust Critical Vulnerability (CVE-2026-1731)](https://unit42.paloaltonetworks.com/beyondtrust-cve-2026-1731/)

* [Bash](https://unit42.paloaltonetworks.com/tag/bash/ "bash")

* [CVE-2026-1731](https://unit42.paloaltonetworks.com/tag/cve-2026-1731/ "CVE-2026-1731")

* [PowerShell](https://unit42.paloaltonetworks.com/tag/powershell/ "PowerShell")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/beyondtrust-cve-2026-1731/ "VShell and SparkRAT Observed in Exploitation of BeyondTrust Critical Vulnerability (CVE-2026-1731)")  
  ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/02/AdobeStock_1020436911-786x440.jpeg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) February 17, 2026 [#### Critical Vulnerabilities in Ivanti EPMM Exploited](https://unit42.paloaltonetworks.com/ivanti-cve-2026-1281-cve-2026-1340/)

* [CVE-2026-1281](https://unit42.paloaltonetworks.com/tag/cve-2026-1281/ "CVE-2026-1281")

* [CVE-2026-1340](https://unit42.paloaltonetworks.com/tag/cve-2026-1340/ "CVE-2026-1340")

* [Ivanti](https://unit42.paloaltonetworks.com/tag/ivanti/ "Ivanti")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ivanti-cve-2026-1281-cve-2026-1340/ "Critical Vulnerabilities in Ivanti EPMM Exploited")  
  ![Pictorial representation of CVE-2025-0921. Digital illustration of a map of North America with interconnected glowing lines and dots symbolizing network connections across the continent.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/01/06_Vulnerabilities_1920x900-2-1-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) January 30, 2026 [#### Privileged File System Vulnerability Present in a SCADA System](https://unit42.paloaltonetworks.com/iconics-suite-cve-2025-0921/)

* [CVE-2025-0921](https://unit42.paloaltonetworks.com/tag/cve-2025-0921/ "CVE-2025-0921")

* [Privilege escalation](https://unit42.paloaltonetworks.com/tag/privilege-escalation/ "privilege escalation")

* [SCADA](https://unit42.paloaltonetworks.com/tag/scada/ "SCADA")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/iconics-suite-cve-2025-0921/ "Privileged File System Vulnerability Present in a SCADA System")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/unit42-footer-subscribe-desktop.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Get updates from Unit 42

## Peace of mind comes from staying ahead of threats. Subscribe today.

Your Email

Subscribe for email updates to all Unit 42 threat research.  
By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use "Terms of Use") and acknowledge our [Privacy Statement.](https://www.paloaltonetworks.com/legal-notices/privacy "Privacy Statement")

This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.

Invalid captcha!
Subscribe ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/ot-security-solution)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase)

* [Prisma SASE](https://www.paloaltonetworks.com/sase)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/unit42/respond/managed-detection-response)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42)

* [Prepare for Emerging Risks](https://www.paloaltonetworks.com/unit42/prepare-for-emerging-risks/continuous-frontier-ai-defense)

* [Strengthen Your Defenses](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses)

* [Build Your Security Strategy](https://www.paloaltonetworks.com/unit42/build-your-security-strategy)

* [Understand the Adversary](https://www.paloaltonetworks.com/unit42/threat-intelligence)

* [Respond to a Cyber Attack](https://www.paloaltonetworks.com/unit42/respond)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [Customers](https://www.paloaltonetworks.com/customers)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/)

* [Communities](https://www.paloaltonetworks.com/communities)

* [Content Library](https://www.paloaltonetworks.com/resources)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure)

* [Sitemap](https://www.paloaltonetworks.com/sitemap)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use)

* [Documents](https://www.paloaltonetworks.com/legal)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* EN  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
