Windows AD SPN Unicode Collision Injection
The following analytic detects the addition of a servicePrincipalName (SPN) containing invisible Unicode characters to an Active Directory computer object via Windows Security Event 5136. This is the key indicator of…
Description
The following analytic detects the addition of a servicePrincipalName (SPN) containing invisible Unicode characters to an Active Directory computer object via Windows Security Event 5136. This is the key indicator of the KerberLoss attack (CVE-2026-25177), where an attacker with write access to a machine account's SPN attribute injects a collision SPN that contains a Zero Width or other invisible Unicode character (e.g. U+200C Zero Width Non-Joiner). LDAP's string preparation rules (RFC 4518) cause these characters to be ignored during uniqueness checking, allowing the write to succeed even when an identical SPN already exists on another machine account. The Kerberos KDC, however, does not apply the same normalisation — it finds two accounts with matching SPNs and returns KDC_ERR_S_PRINCIPAL_UNKNOWN, causing a Kerberos denial-of-service or forcing clients to fall back to NTLM downgrade.
Detection logic
Detection requirements
- Platform
- LinuxmacOSWindows
The rule states no platform. This is derived from the ATT&CK technique it maps to.
- Log source category
- windows_event_log_security_5136
Known benign triggers
- Legitimate use of invisible Unicode characters in SPN values is not expected. This detection should have a very low false positive rate. Provisioning tools or scripts that incorrectly encode SPN strings from certain character sets may trigger this. Verify the SubjectUserName and ObjectDN to confirm intent.
MITRE ATT&CK mappings
0 exclusive techniques.This is coverage no other published rule has; it is not this rule's total technique count.
References
| Reference | Cited by |
|---|---|
| learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-5136 | 6from 2 sources |
| msrc.microsoft.com/update-guide/vulnerability/CVE-2026-25177 | 2 |
| www.semperis.com/blog/identity-crisis-novel-vulnerabilities-leading-to-kerberos-downgrade-dos-and-full-domain-takeover/ | 2 |
From the source
- At source
- Open at source
- Upstream identifier
- d2d2c043-57a6-4aca-be43-ebb402dbb9e5
- Tagged by the source as
- Active Directory Kerberos AttacksCompromised User AccountSneaky Active Directory Persistence TricksEndpointendpointSplunk CloudSplunk EnterpriseSplunk Enterprise Securityendpoint
Licence
- Published under
- Apache License 2.0Read the licence
- Attribution
- Required
- Obtained under
- Apache-2.0Read the origin licence
Authorship
- Written by
- Published
- Oct 6, 2026
- Version
- 1