Analytics BIOC Low

Possible Kerberos relay attack

A suspicious local network login was observed, which might indicate on Kerberos relay attack. This attack can lead to privilege escalation by obtaining system privileges on the target.

Module:
Platform Analytics
Data source:
Windows Event Collector, XDR Agent
ATT&CK tactics: Privilege Escalation (TA0004)
ATT&CK techniques: Abuse Elevation Control Mechanism (T1548)
Attacker's goals:

An attacker is attempting to elevate its privileges on the machine.

Investigative actions:

Check for any other suspicious activity related to the host involved in the alert. Look for a new machine that was added to the domain.

Test period:
N/A (single event)
Deduplication:
2 Days