Analytics BIOC
Informational
✕
PKINIT TGT authentication request
A Kerberos TGT was requested using PKINIT. This may indicate an attack on Active Directory Certificate Services (AD CS), such as shadow credential exploitation or certificate-based authentication abuse.
- Module:
- Identity Analytics
- Data source:
- Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Lateral Movement (TA0008) Privilege Escalation (TA0004)
ATT&CK techniques: Use Alternate Authentication Material (T1550) Valid Accounts (T1078)
Detector tags: Active Directory Certificate Services Analytics
Attacker's goals:
Gain unauthorized access to high-privilege accounts by abusing certificate-based authentication mechanisms.
Investigative actions:
Verify if Windows Hello for Business (WHfB) is deployed and actively used in the environment, as it may explain the PKINIT activity. Inspect the Key Credentials attribute of the target account for recent modifications. Review associated service tickets or lateral movement activities tied to the target account. Investigate unusual certificate issuance or PKI activities.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
2 variations:
- Suspicious PKINIT TGT authentication request Medium (parent: Informational)
- Abnormal PKINIT TGT authentication request Low (parent: Informational)