Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0522 — Detect Kerberos Ticket Theft or Forgery (T1558)
DET0522

Detect Kerberos Ticket Theft or Forgery (T1558)

3 analytic(s) · 1 technique(s) detected

Analytics

3
AN1443 Analytic 1443
Windows

Detects anomalous Kerberos activity such as forged or stolen tickets by correlating malformed fields in logon events, RC4-encrypted TGTs, or TGS requests without corresponding TGT requests. Also detects suspicious processes accessing LSASS memory for ticket extraction.

WinEventLog:Security EventCode=4672, 4634 WinEventLog:Sysmon EventCode=10
[TicketLifetimeThreshold] Threshold for Kerberos TGT lifetimes deviating from domain defaults.
[EncryptionTypes] Monitor for downgraded encryption types (e.g., RC4) in Kerberos tickets.
[ProcessAllowlist] List of expected processes accessing LSASS; deviations may be suspicious.
AN1444 Analytic 1444
Linux

Detects suspicious access to SSSD secrets database and Kerberos key material indicating ticket theft or replay attempts. Correlates anomalous file access with unusual Kerberos service ticket requests.

auditd:SYSCALL Access to /var/lib/sss/secrets/secrets.ldb or .secrets.mkey linux:syslog Unusual kinit or klist activity
[SecretsAccessThreshold] Alert threshold for frequency of access to Kerberos secrets files.
[UnusualServiceAccounts] Baseline accounts normally performing Kerberos requests; anomalies flagged.
AN1445 Analytic 1445
macOS

Detects attempts to forge or replay Kerberos tickets by monitoring Unified Logs for anomalous kinit/klist activity and correlating unusual authentication sequences.

macos:unifiedlog Unusual Kerberos TGS-REQ without TGT or anomalous ticket lifetime
[TicketRequestPatterns] Expected sequence of TGT followed by TGS requests; deviations may indicate forgery.
[TicketLifetime] Expected ticket lifetimes; anomalies may indicate Golden or Silver Tickets.

Detected Techniques

1

Details

MITRE ID
DET0522
STIX ID
x-mitre-detection-strategy--3638f523-dc38-4ff0-8682-d2027af5bd77
Analytics
3
Techniques Detected
1
By Tactic
Credential Access
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.