Cross-source coverage

T1558 / ATT&CK

Steal or Forge Kerberos Tickets

92 rules · 91 families across 7 sources.

Showing deprecated rules · back to the default

From MITRE ATT&CK 19.2

Adversaries may attempt to subvert Kerberos authentication by stealing or forging Kerberos tickets to enable Pass the Ticket. Kerberos is an authentication protocol widely used in modern Windows domain environments. In Kerberos environments, referred to as “realms”, there are three basic participants: client, service, and Key Distribution Center (KDC). Clients request access to a service and through the exchange of Kerberos tickets, originating from KDC, they are granted access after having successfully authenticated. The KDC is responsible for both authentication and ticket granting. Adversaries may attempt to abuse Kerberos by stealing tickets or forging tickets to enable unauthorized access.

On Windows, the built-in klist utility can be used to list and analyze cached Kerberos tickets.

Platforms
Linux · macOS · Windows
Telemetry
WinEventLog:SecurityWinEventLog:Sysmonauditd:SYSCALLlinux:syslogmacos:unifiedlog

How MITRE says to detect it DET0522

Detect Kerberos Ticket Theft or Forgery (T1558)

Windows Analytic 1443

Detects anomalous Kerberos activity such as forged or stolen tickets by correlating malformed fields in logon events, RC4-encrypted TGTs, or TGS requests without corresponding TGT requests. Also detects suspicious processes accessing LSASS memory for ticket extraction.

  • WinEventLog:Security EventCode=4672, 4634
  • WinEventLog:Sysmon EventCode=10

Linux Analytic 1444

Detects suspicious access to SSSD secrets database and Kerberos key material indicating ticket theft or replay attempts. Correlates anomalous file access with unusual Kerberos service ticket requests.

  • auditd:SYSCALL Access to /var/lib/sss/secrets/secrets.ldb or .secrets.mkey
  • linux:syslog Unusual kinit or klist activity

macOS Analytic 1445

Detects attempts to forge or replay Kerberos tickets by monitoring Unified Logs for anomalous kinit/klist activity and correlating unusual authentication sequences.

  • macos:unifiedlog Unusual Kerberos TGS-REQ without TGT or anomalous ticket lifetime

Sub-techniques with coverage

Counted in the 92 above — a rule tagged a sub-technique covers this technique too.


SigmaHQ/sigma

26 rules
Detection Severity Format
Antivirus - Password Dumper Signature Critical Sigma
DC Machine Account Network Logon from Non-DC Source IP Critical Sigma
HackTool - Mimikatz Kirbi File Creation Critical Sigma
HackTool - Rubeus Execution Critical Sigma
DC Machine Account TGS Request from Non-DC Source IP High Sigma
DC Machine Account TGT Request from Non-DC Source IP High Sigma
HackTool - KrbRelay Execution High Sigma
HackTool - KrbRelayUp Execution High Sigma
HackTool - RemoteKrbRelay Execution High Sigma
HackTool - Rubeus Execution - ScriptBlock High Sigma

+ 16 more from SigmaHQ/sigma → showing the 10 highest-severity

splunk/security_content

19 rules
Detection Severity Format
Disabled Kerberos Pre-Authentication Discovery With Get-ADUser Undefined SPL
Disabled Kerberos Pre-Authentication Discovery With PowerView Undefined SPL
Kerberoasting spn request with RC4 encryption Undefined SPL
Kerberos Pre-Authentication Flag Disabled in UserAccountControl Undefined SPL
Kerberos Pre-Authentication Flag Disabled with PowerShell Undefined SPL
Kerberos Service Ticket Request Using RC4 Encryption Undefined SPL
Rubeus Command Line Parameters Undefined SPL
ServicePrincipalNames Discovery with PowerShell Undefined SPL
ServicePrincipalNames Discovery with SetSPN Undefined SPL
Unusual Number of Kerberos Service Tickets Requested Undefined SPL

+ 9 more from splunk/security_content → showing the 10 highest-severity

elastic/detection-rules

18 rules
Detection Severity Format
Potential Invoke-Mimikatz PowerShell Script Critical Elastic TOML
Kerberos Cached Credentials Dumping High Elastic TOML
Kirbi File Creation High Elastic TOML
KRBTGT Delegation Backdoor High Elastic TOML
Potential Kerberos Attack via Bifrost High Elastic TOML
Potential Privilege Escalation via Local Kerberos Relay over LDAP High Elastic TOML
PowerShell Kerberos Ticket Dump High Elastic TOML
PowerShell Kerberos Ticket Request High Elastic TOML
Sensitive Privilege SeEnableDelegationPrivilege assigned to a Principal High Elastic TOML
Service Creation via Local Kerberos Authentication High Elastic TOML

+ 8 more from elastic/detection-rules → showing the 10 highest-severity

socfortress/Wazuh-Rules

16 rules
Detection Severity Format
Sysmon - Event 1: Process creation · Golden Ticket Attack with mimikatz.exe (T1558.001) High Wazuh XML
Sysmon - Event 1: Process creation · Golden Ticket Attack with rubeus.exe (T1558.001) High Wazuh XML
Sysmon - Event 1: Process creation · Invoke-Rubeus PowerSharpPack (T1558.004) High Wazuh XML
Sysmon - Event 1: Process creation · Kerberoasting using setspn.exe (T1558.003) High Wazuh XML
Sysmon - Event 1: Process creation · Klist Purge Ticket Cleanup (T1558.002) High Wazuh XML
Sysmon - Event 1: Process creation · Mimikatz Silver Ticket Command (T1558.002) High Wazuh XML
Sysmon - Event 1: Process creation · PowerSharpPack Rubeus Kerberoasting (T1558.003) High Wazuh XML
Sysmon - Event 1: Process creation · PowerShell Invoke-Kerberoast (T1558.003) High Wazuh XML
Sysmon - Event 1: Process creation · PowerView Get-DomainUser PreauthNotRequired (T1558.004) High Wazuh XML
Sysmon - Event 1: Process creation · Rubeus ASREPRoast (T1558.004) High Wazuh XML

+ 6 more from socfortress/Wazuh-Rules → showing the 10 highest-severity

elastic/protections-artifacts

9 rules
Detection Severity Format
LDAP Search followed by Kerberos Connection Undefined Elastic TOML
Potential Access to Kerberos Cached Credentials Undefined Elastic TOML
Potential Credential Access via Mimikatz Undefined Elastic TOML
Potential Credential Access via Rubeus Undefined Elastic TOML
Potential Kerberos Attack via Bifrost Undefined Elastic TOML
Privilege Escalation via NTLMRelay2Self Undefined Elastic TOML
Suspicious Credential Files Creation via Kerberos Undefined Elastic TOML
Unusual Kerberos Client Process Undefined Elastic TOML
Unusual LDAP Client Process Undefined Elastic TOML

Bert-JanP/Hunting-Queries-Detection-Rules

3 rules
Detection Severity Format
Kerberos attacks Undefined KQL
MITRE ATT&CK Mapping Undefined KQL
Potential Kerberos Encryption Downgrade Undefined KQL

Azure/Azure-Sentinel

1 rule
Detection Severity Format
Potential Kerberoasting Medium KQL

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.