Detecting Pass The Ticket Attacks

Detect Kerberos Pass-the-Ticket (PtT) attacks by analyzing Windows Event IDs 4768, 4769, and 4771 for anomalous ticket usage patterns in Splunk and Elastic SIEM

xalgord ac3df39 3.5 KB Updated

File contents

xalgord/xalgorix/tree/main/internal/tools/skills/data/threat-detection/detecting-pass-the-ticket-attacks commit ac3df39b94

Frequently asked questions

npx skillmds@latest add xalgord/detecting-pass-the-ticket-attacks