logo

Capture the Kerberos Flag: Detecting Kerberos Anomalies

ID: 3156ab75-0567-5eb0-8555-e67dbf1b03d7

STIX ID: report--3156ab75-0567-5eb0-8555-e67dbf1b03d7

Feed Name: NVISO Labs

Threat Score
30/100

Date Published: 2026-02-12

Date Updated: 2026-05-13

Author: Thomas Papaloukas

...
...

This blog explains how to decode Kerberos TGT TicketOptions from Windows Event ID 4768, identifies suspicious flag combinations (including ones used by offensive tools such as Metasploit), and provides a KQL query to hunt for TGT requests that include those flags as indicators of potential Kerberos ticket abuse; it recommends expanding baseline flag sets and enriching detections for ongoing monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.