Back to results

Windows AD SPN Unicode Collision Injection

The following analytic detects the addition of a servicePrincipalName (SPN) containing invisible Unicode characters to an Active Directory computer object via Windows Security Event 5136. This is the key indicator of…

Description

The following analytic detects the addition of a servicePrincipalName (SPN) containing invisible Unicode characters to an Active Directory computer object via Windows Security Event 5136. This is the key indicator of the KerberLoss attack (CVE-2026-25177), where an attacker with write access to a machine account's SPN attribute injects a collision SPN that contains a Zero Width or other invisible Unicode character (e.g. U+200C Zero Width Non-Joiner). LDAP's string preparation rules (RFC 4518) cause these characters to be ignored during uniqueness checking, allowing the write to succeed even when an identical SPN already exists on another machine account. The Kerberos KDC, however, does not apply the same normalisation — it finds two accounts with matching SPNs and returns KDC_ERR_S_PRINCIPAL_UNKNOWN, causing a Kerberos denial-of-service or forcing clients to fall back to NTLM downgrade.

Detection logic

Detection requirements

Platform
LinuxmacOSWindows

The rule states no platform. This is derived from the ATT&CK technique it maps to.

Known benign triggers

  • Legitimate use of invisible Unicode characters in SPN values is not expected. This detection should have a very low false positive rate. Provisioning tools or scripts that incorrectly encode SPN strings from certain character sets may trigger this. Verify the SubjectUserName and ObjectDN to confirm intent.

Detections can measure how the public catalogue is used — which detections people look for, and which pages bring them here. It sets a cookie that recognises this browser for 180 days. It is never linked to an account and never follows you to other sites. Privacy notice