Analytics Medium

Kerberos User Enumeration

A high amount of Kerberos principal unknown errors were generated on users in the last hour. This may be indicative of Kerberos user enumeration.

Module:
Identity Analytics
Data source:
Palo Alto Networks Firewall traffic Logs, XDR Agent
ATT&CK tactics: Discovery (TA0007)
ATT&CK techniques: Account Discovery (T1087)
Attacker's goals:

The attacker may attempt to gain an initial foothold in the domain by enumerating users and finding service accounts.

Investigative actions:

Check whether any service principal names (SPNs) were not set correctly, as they will always return a principal unknown error.

Test period:
1 Hour
Deduplication:
1 Day