Network Anomaly Detection in KATA
ID: 3f3e6e45-b79f-5305-a9e8-131523a85a88
STIX ID: report--3f3e6e45-b79f-5305-a9e8-131523a85a88
Feed Name: Securelist by Kaspersky
Date Published: 2026-07-31
Date Updated: 2026-07-31
Author: Arseny Vesnovsky, Valery Akulenko, Dmitry Sabadash
This report explains how attackers abuse Kerberos (Kerberoasting) and DNS (TXT-based DNS tunneling) to perform credential theft and covert C2/exfiltration, and demonstrates how Kaspersky Anti Targeted Attack (KATA) Network Anomaly Detection uses behavioral, SQL-based rules (ClickHouse) and configurable variables to detect these anomalies, reduce false positives, and support investigation workflows.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
