BigHugger
sk Skill · mukul975

detecting-golden-ticket-attacks-in-kerberos-logs

Detect Golden Ticket attacks in Active Directory using Splunk and KQL queries against domain controller event logs, looking for Kerberos TGT anomalies such as mismatched encryption types, impossible ticket lifetimes, non-existent accounts, and forged PAC signatures. Use when hunting for Kerberos ticket forgery or krbtgt-based persistence (MITRE T1558.001) in AD environments.

installs 8w
0
30-day movement
starts with the next reading
Related entries
1
Connections
0
kqlPythonmitre-t1558-001active-directorykerberoscredential-abusegolden-ticketsplthreat-hunting
Host repository
mukul975/Anthropic-Cybersecurity-Skills
Version
1.0
Licence
Apache-2.0
Host stars
33k
Host language
Python