Windows AD Computer SPN Modified By User Account
The following analytic detects a user account (non-machine account) adding or removing a servicePrincipalName (SPN) on a computer object in Active Directory, via Windows Security Event 5136. In normal AD operations,…
Description
The following analytic detects a user account (non-machine account) adding or removing a servicePrincipalName (SPN) on a computer object in Active Directory, via Windows Security Event 5136. In normal AD operations, SPN values on computer objects are managed exclusively by the computer account itself (during domain join or name change), by Domain Controllers during replication, or by the SYSTEM/NETWORK SERVICE context — all of which appear as accounts ending in the dollar sign ($) convention. A named user account writing to the servicePrincipalName attribute of a computer object is anomalous and may indicate an attacker with delegated WriteProperty rights over computer accounts performing SPN manipulation.
Detection logic
Detection requirements
- Platform
- LinuxmacOSWindows
The rule states no platform. This is derived from the 2 ATT&CK techniques it maps to.
- Log source category
- windows_event_log_security_5136
Known benign triggers
- Administrators using tools such as setspn.exe, ADSI Edit, or PowerShell AD modules to manually manage SPNs on computer objects will trigger this detection. Service account provisioning workflows and some third-party identity management platforms may also legitimately modify computer SPNs. Review the SubjectUserName, ObjectDN, and spn_values fields to determine if the change is expected. Consider adding known administrative accounts to the filter macro.
MITRE ATT&CK mappings
0 exclusive techniques.This is coverage no other published rule has; it is not this rule's total technique count.
References
| Reference | Cited by |
|---|---|
| learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-5136 | 6from 2 sources |
| msrc.microsoft.com/update-guide/vulnerability/CVE-2026-25177 | 2 |
| www.semperis.com/blog/identity-crisis-novel-vulnerabilities-leading-to-kerberos-downgrade-dos-and-full-domain-takeover/ | 2 |
From the source
- At source
- Open at source
- Upstream identifier
- dbe30a35-b56d-4a7a-82c4-2433da06b342
- Tagged by the source as
- Active Directory Kerberos AttacksCompromised User AccountSneaky Active Directory Persistence TricksEndpointendpointSplunk CloudSplunk EnterpriseSplunk Enterprise Securityendpoint
Licence
- Published under
- Apache License 2.0Read the licence
- Attribution
- Required
- Obtained under
- Apache-2.0Read the origin licence
Authorship
- Written by
- Published
- Oct 6, 2026
- Version
- 1