A new machine attempted Kerberos delegation
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
12 Hours
Deduplication Period
1 Day
Required Data
Requires one of the following data sources: Windows Event Collector OR XDR Agent with eXtended Threat Hunting (XTH)
Detection Modules
Identity Analytics
ATT&CK Tactic
Privilege Escalation (TA0004)
ATT&CK Technique
Abuse Elevation Control Mechanism (T1548)
Severity
Medium
Description
A newly created machine attempted to perform a Kerberos delegation. This suspicious activity might indicate a Kerberos relay attack.
Attacker's Goals
Elevate privileges from standard domain user to system.
Investigative actions
Check for any other suspicious activity related to the machine involved in the alert.
Look for a new machine that was added to the domain.
PreviousA new Azure email domain verification was requested
NextA New Server was Added to an Azure Active Directory Hybrid Health ADFS Environment
Was this helpful?
