logo

Threat Hunting Use Case: Windows Authentication Attacks

ID: 300f9cd4-ecee-5fcc-b572-8628d123b117

STIX ID: report--300f9cd4-ecee-5fcc-b572-8628d123b117

Feed Name: ReliaQuest Blog

Date Published: 2020-10-09

Date Updated: 2026-04-29

...
...

Executive Summary: This document provides a Windows Authentication Attacks threat-hunting use case that maps relevant MITRE ATT&CK techniques (T1078, T1110, T1558, T1098, T1550, T1136) to Windows Security Event Logs and outlines detection objectives, key event IDs to monitor (4624, 4625, 4672, 4676, 4769, 4720), behaviors to look for (brute force/password spraying, Pass-the-Hash, Kerberoasting, abnormal account creation and privilege use), and a recommended hunt duration of 30–90 days to help identify and reduce authentication-based threats.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.