Detecting Pass The Ticket Attacks

Detect Kerberos Pass-the-Ticket (PtT) attacks by analyzing Windows Event IDs 4768, 4769, and 4771 for anomalous ticket usage patterns in Splunk and Elastic SIEM

26zl cdaec04 4 files · 23.8 KB Updated

File contents

26zl/cybersec-toolkit/tree/main/.claude/skills/detecting-pass-the-ticket-attacks commit cdaec04ae3

Frequently asked questions

npx skillmds@latest add 26zl/detecting-pass-the-ticket-attacks