Analytics BIOC Medium

TGT request with a spoofed sAMAccountName - Network

A Kerberos authentication ticket (TGT) was requested for an account with a spoofed sAMAccountName.

Module:
Identity Analytics
Data source:
XDR Agent
ATT&CK tactics: Privilege Escalation (TA0004) Persistence (TA0003)
ATT&CK techniques: Account Manipulation (T1098) Valid Accounts (T1078)
Attacker's goals:

Elevate privileges from standard domain user to domain admin.

Investigative actions:

Check if the domain controller is patched or vulnerable to the attack. Look for associated sAMAccountName rename events. Check if any associated service tickets were granted. Follow actions by the account and if it performed a DCSync.

Test period:
N/A (single event)
Deduplication:
3 Hours