Possible authentication coercion
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent with eXtended Threat Hunting (XTH)
Detection Modules
Identity Analytics
ATT&CK Tactic
Credential Access (TA0006)
ATT&CK Technique
Forced Authentication (T1187), Adversary-in-the-Middle: LLMNR/NBT-NS Poisoning and SMB Relay (T1557.001)
Severity
Informational
Description
An unusual Remote Procedure Call (RPC) was made to potentially cause authentication coercion.
Attacker's Goals
An attacker can abuse Remote Procedure Calls to coerce authentication from servers.
Investigative actions
Check for a suspicious process on the initiator.
Check if the source host is a vulnerability scanner.
Check for unusual connections from {actor_remote_ip} to other servers in the network.
Check for logged-in users to {actor_remote_ip} and investigate their actions.
Check for indicators of compromise on {actor_remote_ip}.
Variations
Was this helpful?
