Threat Hunting Use Case: Windows Authentication Hygiene
ID: 11db0755-2263-547d-9721-2b62644177d2
STIX ID: report--11db0755-2263-547d-9721-2b62644177d2
Feed Name: ReliaQuest Blog
This ReliaQuest blog-style use case describes a Windows authentication hygiene threat-hunting campaign: it recommends establishing baselines for usernames, hostnames, Kerberos/NTLM usage, and Windows security event logging to reduce noise and improve detection of authentication attacks (e.g., Kerberoasting, password spraying). The document lists relevant event IDs, MITRE techniques, investigative checks (naming conventions, weak Kerberos encryption, NTLM usage, privileged interactive logons, authentication failure trends), and outcomes to help security teams prioritize and refine hunts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
