Analytics BIOC
Low
✕
Possible Kerberos relay attack
A suspicious local network login was observed, which might indicate on Kerberos relay attack. This attack can lead to privilege escalation by obtaining system privileges on the target.
- Module:
- Platform Analytics
- Data source:
- Windows Event Collector, XDR Agent
ATT&CK tactics: Privilege Escalation (TA0004)
ATT&CK techniques: Abuse Elevation Control Mechanism (T1548)
Attacker's goals:
An attacker is attempting to elevate its privileges on the machine.
Investigative actions:
Check for any other suspicious activity related to the host involved in the alert. Look for a new machine that was added to the domain.
- Test period:
- N/A (single event)
- Deduplication:
- 2 Days