Possible compromised machine account
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent
ATT&CK Tactic
Execution (TA0002)
ATT&CK Technique
User Execution (T1204)
Severity
Medium
Description
A Kerberos TGT for machine account has been used and does not match the hostname.
Attacker's Goals
Gain a special user Kerberos ticket to move laterally.
Investigative actions
Check the source host for possible credential dumping.
Check the delegated account credentials and if it has high privileges.
Check the ticket destination to verify whether it is a sensitive asset.
PreviousPossible collection of screen captures with Windows Problem Steps Recorder
NextPossible ConsentFix - OAuth Token Theft Detected
Was this helpful?
