Analytics
Low
✕
Suspicious Kerberos Pre-Auth Failures by Host
An endpoint failed unusual number of Kerberos pre-authentications (TGT requests) which may indicate a password-spraying attack.
- Module:
- Identity Analytics
- Data source:
- XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Credential Access (TA0006)
ATT&CK techniques: Brute Force: Password Spraying (T1110.003)
Attacker's goals:
The attacker is attempting to gain an initial foothold in the domain using a list of valid users and a guessed password.
Investigative actions:
Identify the source host from which the failed logons originated, by making sure the IP is not a shared address. Review source host activity to detect any additional suspicious or lateral movement behavior. Correlate successful logons from the source host to identify potential account compromises following the failed attempts.
- Test period:
- 10 Minutes
- Deduplication:
- 1 Day