The Client/Server Relationship — A Match Made In Heaven
ID: 215386e0-8bda-55ac-842b-5df87bd2c868
STIX ID: report--215386e0-8bda-55ac-842b-5df87bd2c868
Feed Name: TrustedSec blog
Threat Score
This post presents detection engineering guidance for Kerberos-based attacks, advocating richer client/server correlation (e.g., Event ID 4769 combined with process creation, logon and network telemetry) to infer attacker intent. It covers common use cases such as ASKTGT, S4U2Self and U2U, includes POCs and Splunk examples, and discusses techniques to reduce false positives when detecting anomalous Kerberos activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
