AN1443
Analytic 1443
Windows
Detects anomalous Kerberos activity such as forged or stolen tickets by correlating malformed fields in logon events, RC4-encrypted TGTs, or TGS requests without corresponding TGT requests. Also detects suspicious processes accessing LSASS memory for ticket extraction.
WinEventLog:Security
EventCode=4672, 4634
WinEventLog:Sysmon
EventCode=10
[TicketLifetimeThreshold]
Threshold for Kerberos TGT lifetimes deviating from domain defaults.
[EncryptionTypes]
Monitor for downgraded encryption types (e.g., RC4) in Kerberos tickets.
[ProcessAllowlist]
List of expected processes accessing LSASS; deviations may be suspicious.
AN1444
Analytic 1444
Linux
Detects suspicious access to SSSD secrets database and Kerberos key material indicating ticket theft or replay attempts. Correlates anomalous file access with unusual Kerberos service ticket requests.
auditd:SYSCALL
Access to /var/lib/sss/secrets/secrets.ldb or .secrets.mkey
linux:syslog
Unusual kinit or klist activity
[SecretsAccessThreshold]
Alert threshold for frequency of access to Kerberos secrets files.
[UnusualServiceAccounts]
Baseline accounts normally performing Kerberos requests; anomalies flagged.
AN1445
Analytic 1445
macOS
Detects attempts to forge or replay Kerberos tickets by monitoring Unified Logs for anomalous kinit/klist activity and correlating unusual authentication sequences.
macos:unifiedlog
Unusual Kerberos TGS-REQ without TGT or anomalous ticket lifetime
[TicketRequestPatterns]
Expected sequence of TGT followed by TGS requests; deviations may indicate forgery.
[TicketLifetime]
Expected ticket lifetimes; anomalies may indicate Golden or Silver Tickets.