Analytics Medium

A new machine attempted Kerberos delegation

A newly created machine attempted to perform a Kerberos delegation. This suspicious activity might indicate a Kerberos relay attack.

Module:
Identity Analytics
Data source:
Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Privilege Escalation (TA0004)
ATT&CK techniques: Abuse Elevation Control Mechanism (T1548)
Attacker's goals:

Elevate privileges from standard domain user to system.

Investigative actions:

Check for any other suspicious activity related to the machine involved in the alert. Look for a new machine that was added to the domain.

Test period:
12 Hours
Deduplication:
1 Day