Weakly-Encrypted Kerberos Ticket Requested
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
30 Days
Required Data
Requires one of the following data sources: Palo Alto Networks Firewall traffic Logs OR XDR Agent
ATT&CK Tactic
Credential Access (TA0006)
ATT&CK Technique
Steal or Forge Kerberos Tickets: Kerberoasting (T1558.003)
Severity
Low
Description
A user specifically requested weak and deprecated encryption in a Kerberos TGS request. This provides easy-to-crack hashes and is typically a sign of a Kerberoasting attack.
Attacker's Goals
Crack account credentials by obtaining an easy-to-crack Kerberos ticket.
Investigative actions
Check who used the host at the time of the alert to rule out a benign service or tool requesting weak Kerberos encryption.
Variations
PreviousWeakly-Encrypted Kerberos TGT Response
NextWeb server CGO executed a process following a potential Webshell dropped
Was this helpful?
