logo

Detection engineering rabbit holes — parsing ASN.1 packets in KQL

ID: d03c64ab-6c24-58c8-ae5b-d82b16e0949a

STIX ID: report--d03c64ab-6c24-58c8-ae5b-d82b16e0949a

Feed Name: FalconForce

Date Published: 2024-12-16

Date Updated: 2026-04-27

Author: Olaf Hartong

...
...

This write-up presents a detection approach for Kerberos TGS-REQ patterns associated with Rubeus by parsing MDE DeviceNetworkEvents SamplePacketContent to reconstruct ticketOptions and match characteristic flag combinations (forwardable, renewable, renewable_ok) while excluding forwarded, with complete KQL provided. It highlights significant limitations—Rubeus opsec mode evasion, packet truncation in sampled telemetry, and incomplete MDE exposure of flags—that currently render the detection largely ineffective. Despite limited outcomes, the methodology and parsing techniques are applicable to other Kerberos tooling and network events.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.