For the complete documentation index, see llms.txt. This page is also available as Markdown.

A new machine attempted Kerberos delegation

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

12 Hours

Deduplication Period

1 Day

Required Data

Requires one of the following data sources: Windows Event Collector OR XDR Agent with eXtended Threat Hunting (XTH)

Detection Modules

Identity Analytics

ATT&CK Tactic

Privilege Escalation (TA0004)

ATT&CK Technique

Abuse Elevation Control Mechanism (T1548)

Severity

Medium

Description

A newly created machine attempted to perform a Kerberos delegation. This suspicious activity might indicate a Kerberos relay attack.

Attacker's Goals

Elevate privileges from standard domain user to system.

Investigative actions

  • Check for any other suspicious activity related to the machine involved in the alert.

  • Look for a new machine that was added to the domain.

Was this helpful?