Analytics
Medium
✕
Kerberos User Enumeration
A high amount of Kerberos principal unknown errors were generated on users in the last hour. This may be indicative of Kerberos user enumeration.
- Module:
- Identity Analytics
- Data source:
- Palo Alto Networks Firewall traffic Logs, XDR Agent
ATT&CK tactics: Discovery (TA0007)
ATT&CK techniques: Account Discovery (T1087)
Attacker's goals:
The attacker may attempt to gain an initial foothold in the domain by enumerating users and finding service accounts.
Investigative actions:
Check whether any service principal names (SPNs) were not set correctly, as they will always return a principal unknown error.
- Test period:
- 1 Hour
- Deduplication:
- 1 Day