Detecting Pass The Ticket Attacks

Use when detect Kerberos Pass-the-Ticket (PtT) attacks by analyzing Windows Event IDs 4768, 4769, and 4771 for anomalous ticket usage patterns in Splunk and Elastic SIEM. Use when detecting kerberos pass-the-ticket (ptt) attacks by analyzing windows event ids.

oyi77 ceaee1e 4.5 KB Updated 10 repo stars

File contents

oyi77/1ai-skills/tree/main/cybersecurity/detecting-pass-the-ticket-attacks commit ceaee1ed2d

Frequently asked questions

npx skillmds add oyi77/detecting-pass-the-ticket-attacks