Detecting Pass The Ticket Attacks

Detect Kerberos Pass-the-Ticket (PtT) attacks by analyzing Windows Event IDs 4768, 4769, and 4771 for anomalous ticket usage patterns in Splunk and Elastic SIEM

autohandai Updated

File contents

autohandai/community-skills/tree/main/detecting-pass-the-ticket-attacks commit b04ea66a62

Frequently asked questions

npx skillmds@latest add autohandai-community-skills/detecting-pass-the-ticket-attacks