TGT request with a spoofed sAMAccountName - Network
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
3 Hours
Required Data
XDR Agent
Detection Modules
Identity Analytics
ATT&CK Tactic
Privilege Escalation (TA0004), Persistence (TA0003)
ATT&CK Technique
Account Manipulation (T1098), Valid Accounts (T1078)
Severity
Medium
Description
A Kerberos authentication ticket (TGT) was requested for an account with a spoofed sAMAccountName.
Attacker's Goals
Elevate privileges from standard domain user to domain admin.
Investigative actions
Check if the domain controller is patched or vulnerable to the attack.
Look for associated sAMAccountName rename events.
Check if any associated service tickets were granted.
Follow actions by the account and if it performed a DCSync.
PreviousTGT request with a spoofed sAMAccountName - Event log
NextThe CA policy EditFlags was queried
Was this helpful?
