logo

The Client/Server Relationship — A Match Made In Heaven

ID: bc72b69c-d7ae-53fa-b28e-25acc14d5d13

STIX ID: report--bc72b69c-d7ae-53fa-b28e-25acc14d5d13

Feed Name: Binary Defense Blog

Date Published: 2025-08-12

Date Updated: 2026-04-27

...
...

This joint research post presents a correlation-driven detection approach for Kerberos-based attacks, advocating the fusion of primary Windows Security events (e.g., 4769) with secondary context (logon, process, and network telemetry) across client/server boundaries to reveal attacker intent; it includes Splunk examples and a PowerShell-based POC to detect uncommon U2U activity (via KDC option fuzzing and LDAP SPN validation to minimize false positives), and shows how to adapt this methodology to techniques like ASKTGT/ASKTGS, Kerberoasting, and AS-REP Roasting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.