Splunk published two detections for Active Directory service principal name (SPN) manipulation, including the KerberLoss technique associated with CVE-2026-25177, which Microsoft lists as an Active Directory Domain Services elevation-of-privilege vulnerability. According to Splunk, inconsistent normalization between LDAP uniqueness checks and the Kerberos Key Distribution Center allows SPNs containing invisible Unicode characters to collide, potentially disrupting Kerberos authentication or forcing clients to fall back to NTLM. One analytic flags suspicious Unicode in SPN changes; the other detects non-machine accounts adding or removing SPNs on computer objects, activity that can reflect abuse of delegated WriteProperty permissions. Splunk also released an attack-simulation dataset capturing both behaviors; the references do not establish exploitation in the wild.
Both analytics rely on Windows Security Event 5136 and require domain controller Security logs, successful Directory Service Changes auditing, and appropriate WriteProperty audit SACLs on monitored objects. Defenders should verify these prerequisites, enable the detections—which are disabled by default—and investigate the modifying account, affected object, and changed SPN values. Microsoft recommends correlating Value Added and Value Deleted events using their shared Correlation ID to reconstruct attribute changes. Legitimate administration and provisioning can trigger the broader SPN-modification analytic, which produces intermediate risk findings rather than direct notable alerts; the Unicode-collision analytic is expected to generate few false positives. Review delegated SPN-write permissions and distinguish authorized changes from suspicious modifications.

See real exploitation activity before you spend the cycle.
5 events from the most recent confirmed update back to the earliest known activity.
Splunk's dated KerberLoss dataset entry documents an attack_range simulation in which a user account modified computer SPNs and injected invisible Unicode characters. The collected Windows Security logs record the activity through Event 5136; the entry states that no specific detections currently use the dataset for testing.
Splunk updated its Windows AD SPN Unicode Collision Injection detection for KerberLoss, associated with CVE-2026-25177. The analytic examines Event 5136 for invisible Unicode characters in SPNs that could trigger Kerberos denial-of-service or NTLM fallback through inconsistent LDAP and KDC normalization.
Splunk updated its Windows AD Computer SPN Modified By User Account analytic to identify non-machine accounts adding or removing computer servicePrincipalName values through Event 5136. The detection references CVE-2026-25177 and flags activity potentially associated with abuse of delegated WriteProperty permissions.
A Metasploit pull request introduces an auxiliary module for auditing and exercising CVE-2026-25177, with AUDIT, CHECK, HIJACK, and CLEANUP actions tested against an isolated Windows Server 2019 domain controller. The module demonstrates hidden-character SPN resolution through LDAP but warns that requesting and decrypting a service ticket is necessary to establish cryptographically verified ticket hijacking.
Microsoft's vulnerability advisory identifies CVE-2026-25177 as an Active Directory Domain Services elevation-of-privilege vulnerability. The supplied advisory reference provides no patch or exploitation details.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
6 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourceresearch.splunk.com
Open sourceresearch.splunk.com
Open sourceresearch.splunk.com
Open sourcemsrc.microsoft.com
Open sourcelearn.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.