Agent Skills: detecting-pass-the-ticket-attacks
Detect Kerberos Pass-the-Ticket (PtT) attacks by analyzing Windows Event IDs 4768, 4769, and 4771 for anomalous ticket usage patterns in Splunk and Elastic SIEM
UncategorizedID: plurigrid/asi/detecting-pass-the-ticket-attacks
165
Install this agent skill to your local
Skill Files
Browse the full folder contents for detecting-pass-the-ticket-attacks.
Loading file tree…
Select a file to preview its contents.