logo

Threat Hunting Use Case: Windows Authentication Hygiene

ID: 11db0755-2263-547d-9721-2b62644177d2

STIX ID: report--11db0755-2263-547d-9721-2b62644177d2

Feed Name: ReliaQuest Blog

Date Published: 2020-09-17

Date Updated: 2026-04-29

...
...

This ReliaQuest blog-style use case describes a Windows authentication hygiene threat-hunting campaign: it recommends establishing baselines for usernames, hostnames, Kerberos/NTLM usage, and Windows security event logging to reduce noise and improve detection of authentication attacks (e.g., Kerberoasting, password spraying). The document lists relevant event IDs, MITRE techniques, investigative checks (naming conventions, weak Kerberos encryption, NTLM usage, privileged interactive logons, authentication failure trends), and outcomes to help security teams prioritize and refine hunts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.