BIOC Informational

Kerberos brute-force attack using Kerbrute

This is a known Kerbrute tool command, used to conduct Kerberos authentication brute-force attacks.

Module:
Platform Analytics
Agent event type:
Process execution
Category:
Credential Access
Status:
Enabled
ATT&CK tactics: Credential Access (TA0006)
ATT&CK techniques: Brute Force (T1110)
Indicator:

Process action type = execution AND target process cmd = *kerbrute* -domain * -users * -passwords * , *kerbrute* -domain * -passwords * -users * , *kerbrute* -users * -domain * -passwords * , *kerbrute* -users * -passwords * -domain * , *kerbrute* -passwords * -users * -domain * , *kerbrute* -passwords * -domain * -users * , *passwordspray * , *bruteforce * , *bruteuser *

Preventable: yes