Analytics BIOC Medium

TGT request with a spoofed sAMAccountName - Event log

A Kerberos authentication ticket (TGT) was requested for an account with a spoofed sAMAccountName.

Module:
Identity Analytics
Data source:
Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Privilege Escalation (TA0004) Persistence (TA0003)
ATT&CK techniques: Account Manipulation (T1098) Valid Accounts (T1078)
Attacker's goals:

Elevate privileges from standard domain user to domain admin.

Investigative actions:

Check if the domain controller is patched or vulnerable to the attack. Look for associated sAMAccountName rename events. Check if any associated service tickets were granted. Follow actions by the account and if it performed a DCSync.

Test period:
N/A (single event)
Deduplication:
3 Hours