Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source
  • Multiple TGT requests for users without Kerberos pre-authentication Informational Identity Analytics 2 variations

    Multiple TGT requests for users that do not require Kerberos pre-authentication were observed. This is typically a sign of an AS-REP attack.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    10 Minutes
    Deduplication:
    1 Day
    ATT&CK tactics: Credential Access (TA0006)
    ATT&CK techniques: Steal or Forge Kerberos Tickets: AS-REP Roasting (T1558.004)
    Required data: Windows Event Collector XDR Agent with eXtended Threat Hunting (XTH)
    Attacker's goals: Crack account credentials by obtaining an easy-to-crack Kerberos ticket.
    Investigative actions: Check who used the host at the time of the alert, to rule out a benign service or tool requesting weak Kerberos encryption.

    Variations

    An excessive number of TGT requests were sent for users that do not require Kerberos pre-authentication

    Low overridden

    Multiple TGT requests for users that do not require Kerberos pre-authentication were observed. This is typically a sign of an AS-REP attack. overridden

    A TGT request was sent for a user who does not require Kerberos pre-authentication

    Informational overridden

    A TGT request was sent for a user who does not require Kerberos pre-authentication. This might indicate an AS-REP attack. overridden