Detection engineering rabbit holes — parsing ASN.1 packets in KQL
ID: d03c64ab-6c24-58c8-ae5b-d82b16e0949a
STIX ID: report--d03c64ab-6c24-58c8-ae5b-d82b16e0949a
Feed Name: FalconForce
This write-up presents a detection approach for Kerberos TGS-REQ patterns associated with Rubeus by parsing MDE DeviceNetworkEvents SamplePacketContent to reconstruct ticketOptions and match characteristic flag combinations (forwardable, renewable, renewable_ok) while excluding forwarded, with complete KQL provided. It highlights significant limitations—Rubeus opsec mode evasion, packet truncation in sampled telemetry, and incomplete MDE exposure of flags—that currently render the detection largely ineffective. Despite limited outcomes, the methodology and parsing techniques are applicable to other Kerberos tooling and network events.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
