Analytics BIOC Medium

Service ticket request with a spoofed sAMAccountName

A Kerberos service ticket (ST) was requested for an account with a spoofed sAMAccountName.

Module:
Identity Analytics
Data source:
Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Privilege Escalation (TA0004) Persistence (TA0003)
ATT&CK techniques: Account Manipulation (T1098) Valid Accounts (T1078)
Attacker's goals:

Elevate privileges from standard domain user to domain admin.

Investigative actions:

Check if the domain controller is patched or vulnerable to the attack. Look for associated sAMAccountName rename events. Follow actions by the account and if it performed a DCSync.

Test period:
N/A (single event)
Deduplication:
3 Hours