Analytics BIOC
Low
✕
Suspicious setspn.exe execution
A Service Principal Name (SPN) is a unique identifier for a service, mapped to a specific account. Setspn.exe can be used to retrieve SPN information, which may indicate an attacker's attempt to "Kerberoast".
- Module:
- Platform Analytics
- Data source:
- XDR Agent
ATT&CK tactics: Credential Access (TA0006)
ATT&CK techniques: Steal or Forge Kerberos Tickets (T1558)
Attacker's goals:
Retrieving SPN information to perform related attacks like 'Kerberoast'.
Investigative actions:
Investigate the user who executed setspn.exe and find out if the act was malicious.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day