Steal or Forge Kerberos Tickets
Adversaries may attempt to subvert Kerberos authentication by stealing or forging Kerberos tickets to enable [Pass the Ticket](https://attack.mitre.org/techniques/T1550/003). Kerberos is an authentication protocol widely used in modern Windows domain environments. In Kerberos environments, referred to as “realms”, there are three basic participants: client, service, and Key Distribution Center (KDC).(Citation: ADSecurity Kerberos Ring Decoder) Clients request access to a service and through the ...
BY SOURCE
PROCEDURES (18)
Auto-extracted: 3 detections for unusual
Auto-extracted: 2 detections for mimikatz
Auto-extracted: 2 detections for privilege
Auto-extracted: 2 detections for lateral
Auto-extracted: 2 detections for powershell
Auto-extracted: 2 detections for event log
Auto-extracted: 1 detections for persist
Auto-extracted: 1 detections for dump
Auto-extracted: 1 detections for kerbero
Auto-extracted: 1 detections for privilege
Auto-extracted: 1 detections for service
Auto-extracted: 1 detections for persist
Auto-extracted: 1 detections for script execution monitoring
Auto-extracted: 1 detections for credential
Auto-extracted: 1 detections for persist
Auto-extracted: 1 detections for credential
Auto-extracted: 1 detections for kerbero
Auto-extracted: 1 detections for dump