logo

Network Anomaly Detection in KATA

ID: 3f3e6e45-b79f-5305-a9e8-131523a85a88

STIX ID: report--3f3e6e45-b79f-5305-a9e8-131523a85a88

Feed Name: Securelist by Kaspersky

Threat Score
55/100

Date Published: 2026-07-31

Date Updated: 2026-07-31

Author: Arseny Vesnovsky, Valery Akulenko, Dmitry Sabadash

...
...

This report explains how attackers abuse Kerberos (Kerberoasting) and DNS (TXT-based DNS tunneling) to perform credential theft and covert C2/exfiltration, and demonstrates how Kaspersky Anti Targeted Attack (KATA) Network Anomaly Detection uses behavioral, SQL-based rules (ClickHouse) and configurable variables to detect these anomalies, reduce false positives, and support investigation workflows.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.