Detecting Pass The Ticket Attacks

Detect Kerberos Pass-the-Ticket (PtT) attacks by analyzing Windows Event IDs 4768, 4769, and 4771 for anomalous ticket usage patterns in Splunk and Elastic SIEM

theheavenlyd3mon d6bfd40 4 files · 23.8 KB Updated 28 repo stars

File contents

theheavenlyd3mon/hermes-profiles/tree/main/profiles/cyber-blue-soc/skills/Anthropic-Cybersecurity-Skills/skills/detecting-pass-the-ticket-attacks commit d6bfd40744

Frequently asked questions

npx skillmds add theheavenlyd3mon/detecting-pass-the-ticket-attacks