Cross-source coverage
T1558 / ATT&CK
Steal or Forge Kerberos Tickets
91 rules · 90 families across 7 sources.
1 deprecated hidden · include
From MITRE ATT&CK 19.2
Adversaries may attempt to subvert Kerberos authentication by stealing or forging Kerberos tickets to enable Pass the Ticket. Kerberos is an authentication protocol widely used in modern Windows domain environments. In Kerberos environments, referred to as “realms”, there are three basic participants: client, service, and Key Distribution Center (KDC). Clients request access to a service and through the exchange of Kerberos tickets, originating from KDC, they are granted access after having successfully authenticated. The KDC is responsible for both authentication and ticket granting. Adversaries may attempt to abuse Kerberos by stealing tickets or forging tickets to enable unauthorized access.
On Windows, the built-in klist utility can be used to list and analyze cached Kerberos tickets.
- Tactics
- Credential Access
- Platforms
- Linux · macOS · Windows
- Telemetry
-
WinEventLog:SecurityWinEventLog:Sysmonauditd:SYSCALLlinux:syslogmacos:unifiedlog
How MITRE says to detect it DET0522
Detect Kerberos Ticket Theft or Forgery (T1558)
Windows Analytic 1443
Detects anomalous Kerberos activity such as forged or stolen tickets by correlating malformed fields in logon events, RC4-encrypted TGTs, or TGS requests without corresponding TGT requests. Also detects suspicious processes accessing LSASS memory for ticket extraction.
WinEventLog:SecurityEventCode=4672, 4634WinEventLog:SysmonEventCode=10
Linux Analytic 1444
Detects suspicious access to SSSD secrets database and Kerberos key material indicating ticket theft or replay attempts. Correlates anomalous file access with unusual Kerberos service ticket requests.
auditd:SYSCALLAccess to /var/lib/sss/secrets/secrets.ldb or .secrets.mkeylinux:syslogUnusual kinit or klist activity
macOS Analytic 1445
Detects attempts to forge or replay Kerberos tickets by monitoring Unified Logs for anomalous kinit/klist activity and correlating unusual authentication sequences.
macos:unifiedlogUnusual Kerberos TGS-REQ without TGT or anomalous ticket lifetime
Sub-techniques with coverage
Counted in the 91 above — a rule tagged a sub-technique covers this technique too.
SigmaHQ/sigma
26 rules| Detection | Severity | Format |
|---|---|---|
| Antivirus - Password Dumper Signature | Critical | Sigma |
| DC Machine Account Network Logon from Non-DC Source IP | Critical | Sigma |
| HackTool - Mimikatz Kirbi File Creation | Critical | Sigma |
| HackTool - Rubeus Execution | Critical | Sigma |
| DC Machine Account TGS Request from Non-DC Source IP | High | Sigma |
| DC Machine Account TGT Request from Non-DC Source IP | High | Sigma |
| HackTool - KrbRelay Execution | High | Sigma |
| HackTool - KrbRelayUp Execution | High | Sigma |
| HackTool - RemoteKrbRelay Execution | High | Sigma |
| HackTool - Rubeus Execution - ScriptBlock | High | Sigma |
+ 16 more from SigmaHQ/sigma → showing the 10 highest-severity
splunk/security_content
19 rules| Detection | Severity | Format |
|---|---|---|
| Disabled Kerberos Pre-Authentication Discovery With Get-ADUser | Undefined | SPL |
| Disabled Kerberos Pre-Authentication Discovery With PowerView | Undefined | SPL |
| Kerberoasting spn request with RC4 encryption | Undefined | SPL |
| Kerberos Pre-Authentication Flag Disabled in UserAccountControl | Undefined | SPL |
| Kerberos Pre-Authentication Flag Disabled with PowerShell | Undefined | SPL |
| Kerberos Service Ticket Request Using RC4 Encryption | Undefined | SPL |
| Rubeus Command Line Parameters | Undefined | SPL |
| ServicePrincipalNames Discovery with PowerShell | Undefined | SPL |
| ServicePrincipalNames Discovery with SetSPN | Undefined | SPL |
| Unusual Number of Kerberos Service Tickets Requested | Undefined | SPL |
+ 9 more from splunk/security_content → showing the 10 highest-severity
elastic/detection-rules
17 rules| Detection | Severity | Format |
|---|---|---|
| Potential Invoke-Mimikatz PowerShell Script | Critical | Elastic TOML |
| Kerberos Cached Credentials Dumping | High | Elastic TOML |
| Kirbi File Creation | High | Elastic TOML |
| KRBTGT Delegation Backdoor | High | Elastic TOML |
| Potential Kerberos Attack via Bifrost | High | Elastic TOML |
| PowerShell Kerberos Ticket Dump | High | Elastic TOML |
| PowerShell Kerberos Ticket Request | High | Elastic TOML |
| Sensitive Privilege SeEnableDelegationPrivilege assigned to a Principal | High | Elastic TOML |
| Service Creation via Local Kerberos Authentication | High | Elastic TOML |
| Suspicious Kerberos Authentication Ticket Request | High | Elastic TOML |
+ 7 more from elastic/detection-rules → showing the 10 highest-severity
socfortress/Wazuh-Rules
16 rules+ 6 more from socfortress/Wazuh-Rules → showing the 10 highest-severity
elastic/protections-artifacts
9 rules| Detection | Severity | Format |
|---|---|---|
| LDAP Search followed by Kerberos Connection | Undefined | Elastic TOML |
| Potential Access to Kerberos Cached Credentials | Undefined | Elastic TOML |
| Potential Credential Access via Mimikatz | Undefined | Elastic TOML |
| Potential Credential Access via Rubeus | Undefined | Elastic TOML |
| Potential Kerberos Attack via Bifrost | Undefined | Elastic TOML |
| Privilege Escalation via NTLMRelay2Self | Undefined | Elastic TOML |
| Suspicious Credential Files Creation via Kerberos | Undefined | Elastic TOML |
| Unusual Kerberos Client Process | Undefined | Elastic TOML |
| Unusual LDAP Client Process | Undefined | Elastic TOML |
Bert-JanP/Hunting-Queries-Detection-Rules
3 rules| Detection | Severity | Format |
|---|---|---|
| Kerberos attacks | Undefined | KQL |
| MITRE ATT&CK Mapping | Undefined | KQL |
| Potential Kerberos Encryption Downgrade | Undefined | KQL |
Azure/Azure-Sentinel
1 rule| Detection | Severity | Format |
|---|---|---|
| Potential Kerberoasting | Medium | KQL |