Analytics
Medium
✕
A new machine attempted Kerberos delegation
A newly created machine attempted to perform a Kerberos delegation. This suspicious activity might indicate a Kerberos relay attack.
- Module:
- Identity Analytics
- Data source:
- Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Privilege Escalation (TA0004)
ATT&CK techniques: Abuse Elevation Control Mechanism (T1548)
Attacker's goals:
Elevate privileges from standard domain user to system.
Investigative actions:
Check for any other suspicious activity related to the machine involved in the alert. Look for a new machine that was added to the domain.
- Test period:
- 12 Hours
- Deduplication:
- 1 Day