Analytics BIOC Low

Suspicious setspn.exe execution

A Service Principal Name (SPN) is a unique identifier for a service, mapped to a specific account. Setspn.exe can be used to retrieve SPN information, which may indicate an attacker's attempt to "Kerberoast".

Module:
Platform Analytics
Data source:
XDR Agent
ATT&CK tactics: Credential Access (TA0006)
ATT&CK techniques: Steal or Forge Kerberos Tickets (T1558)
Attacker's goals:

Retrieving SPN information to perform related attacks like 'Kerberoast'.

Investigative actions:

Investigate the user who executed setspn.exe and find out if the act was malicious.

Test period:
N/A (single event)
Deduplication:
1 Day