Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0352 — Detection Strategy for T1550.003 - Pass the Ticket (Windows)
DET0352

Detection Strategy for T1550.003 - Pass the Ticket (Windows)

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN1000 Analytic 1000
Windows

Detects unauthorized Kerberos ticket injection by correlating service ticket (TGS - 4769) requests with absent corresponding account logons (4624) and prior Ticket Granting Ticket (TGT - 4768) activity. Highlights anomalous service ticket generation chains involving unexpected users, hosts, or times, and suspicious injection of tickets via mimikatz-like tooling into LSASS memory. Behavior also includes network lateral movement using Kerberos authentication absent expected interactive logon patterns.

WinEventLog:Security EventCode=4769 WinEventLog:Security EventCode=4768 WinEventLog:Security EventCode=4624, 4648 WinEventLog:Sysmon EventCode=10 WinEventLog:Sysmon EventCode=7
[TimeWindow] Defines the correlation window between TGT request (4768) and TGS request (4769)
[HostContextScope] Adjusts the host scoping for correlation of authentication chains and ticket injection
[LSASSAccessAnomalyThreshold] Allows tuning of alerts for ticket injection attempts via LSASS memory access

Detected Techniques

1

Lateral Movement (1)

Details

MITRE ID
DET0352
STIX ID
x-mitre-detection-strategy--5f53739d-3a41-4f7e-a83d-219a0c64e7a1
Analytics
1
Techniques Detected
1
By Tactic
Lateral Movement
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.