Detection engineering rabbit holes — parsing ASN.1 packets in KQL
ID: 06a02681-e816-54ab-837a-4c0bea2b7c5d
STIX ID: report--06a02681-e816-54ab-837a-4c0bea2b7c5d
Feed Name: FalconForce
Threat Score
This blog-style technical analysis demonstrates how to detect Rubeus-style Kerberos TGS requests by parsing ticket option flags from network telemetry (using KQL against MDE DeviceNetworkEvents), provides sample queries, a flag-calculator tool, and discusses caveats such as packet truncation and Rubeus 'opsec' flags that evade detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
