BigHugger
sk Skill · mukul975

detecting-pass-the-ticket-attacks

Detect Kerberos Pass-the-Ticket (PtT) attacks by analyzing Windows Event IDs 4768, 4769, and 4771 for anomalous ticket usage patterns, with detection queries for Splunk and Elastic SIEM. Use when investigating incidents involving stolen or replayed Kerberos tickets, building detection rules or threat hunting queries for ticket abuse, or validating SOC monitoring coverage for credential-theft attack techniques.

installs 8w
0
30-day movement
starts with the next reading
Related entries
1
Connections
0
Pythonwindows-securityelasticcredential-theftactive-directorysplunkpass-the-ticketkerberos
Host repository
mukul975/Anthropic-Cybersecurity-Skills
Version
1.0
Licence
Apache-2.0
Host stars
33k
Host language
Python