Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters. technique: T1558 ✕
Download CSV Show ATT&CK heatmapSuspicious setspn.exe execution Low
A Service Principal Name (SPN) is a unique identifier for a service, mapped to a specific account. Setspn.exe can be used to retrieve SPN information, which may indicate an attacker's attempt to "Kerberoast".
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Credential Access (TA0006)ATT&CK techniques: Steal or Forge Kerberos Tickets (T1558)Required data: XDR AgentAttacker's goals: Retrieving SPN information to perform related attacks like 'Kerberoast'.Investigative actions: Investigate the user who executed setspn.exe and find out if the act was malicious.