Analytics BIOC
Medium
✕
Service ticket request with a spoofed sAMAccountName
A Kerberos service ticket (ST) was requested for an account with a spoofed sAMAccountName.
- Module:
- Identity Analytics
- Data source:
- Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Privilege Escalation (TA0004) Persistence (TA0003)
ATT&CK techniques: Account Manipulation (T1098) Valid Accounts (T1078)
Attacker's goals:
Elevate privileges from standard domain user to domain admin.
Investigative actions:
Check if the domain controller is patched or vulnerable to the attack. Look for associated sAMAccountName rename events. Follow actions by the account and if it performed a DCSync.
- Test period:
- N/A (single event)
- Deduplication:
- 3 Hours