Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0024 — Detect Kerberos Ccache File Theft or Abuse (T1558.005)
DET0024

Detect Kerberos Ccache File Theft or Abuse (T1558.005)

2 analytic(s) · 1 technique(s) detected

Analytics

2
AN0069 Analytic 0069
Linux

Detects unauthorized access, copying, or modification of Kerberos ccache files (krb5cc_%UID% or krb5.ccache) in /tmp or custom paths defined by KRB5CCNAME. Correlates file access with suspicious processes (e.g., credential dumping tools) and subsequent anomalous Kerberos authentication requests from non-standard processes.

auditd:SYSCALL open: File access attempt on /tmp/krb5cc_* or /tmp/krb5.ccache auditd:SYSCALL execve: Execution of klist, kinit, or tools interacting with ccache outside normal user context
[CcachePathBaseline] Expected directories or environment variable (KRB5CCNAME) paths for ccache files in the environment.
[AllowedProcesses] Baseline list of processes legitimately interacting with ccache (e.g., klist, kinit).
[TimeWindow] Correlation window for linking file access, process execution, and Kerberos requests.
AN0070 Analytic 0070
macOS

Detects abnormal interaction with memory-based Kerberos ccache (API:{uuid}) or file-based overrides. Focus on processes attempting to enumerate or extract Kerberos tickets outside of built-in utilities. Detects use of open-source tools (e.g., Bifrost, modified Mimikatz ports) that interact with the Kerberos framework APIs.

macos:unifiedlog Kerberos framework calls to API:{uuid} cache outside normal process lineage macos:osquery Execution of non-standard binaries accessing Kerberos APIs
[KerberosAPIProcessBaseline] Expected processes using the Kerberos framework (e.g., loginwindow, kinit).
[SuspiciousBinaryList] List of tools or binaries not normally expected to query Kerberos ccache entries.
[TimeWindow] Window to link suspicious process activity with Kerberos authentication anomalies.

Detected Techniques

1

Credential Access (1)

Details

MITRE ID
DET0024
STIX ID
x-mitre-detection-strategy--5c4334d0-cda0-4372-8572-fe2a109d39cb
Analytics
2
Techniques Detected
1
By Tactic
Credential Access
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.