logo

Detection engineering rabbit holes — parsing ASN.1 packets in KQL

ID: 06a02681-e816-54ab-837a-4c0bea2b7c5d

STIX ID: report--06a02681-e816-54ab-837a-4c0bea2b7c5d

Feed Name: FalconForce

Threat Score
15/100

Date Published: 2024-12-16

Date Updated: 2026-06-15

Author: Olaf Hartong

...
...

This blog-style technical analysis demonstrates how to detect Rubeus-style Kerberos TGS requests by parsing ticket option flags from network telemetry (using KQL against MDE DeviceNetworkEvents), provides sample queries, a flag-calculator tool, and discusses caveats such as packet truncation and Rubeus 'opsec' flags that evade detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.