Skip to main content

detecting-pass-the-ticket-attacks

Detects Kerberos Pass-the-Ticket attacks by analyzing Windows Event IDs for anomalous ticket usage patterns in Splunk and Elastic SIEM.

Install this skill

or
detecting-pass-the-ticket-attacks3 files

Comments

Sign in to leave a comment.

No comments yet. Be the first to comment!
Installation guide →