This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Suspicious Kerberos Ticket Request via CLI
Original Source:
[Sigma source]
Title:
Suspicious Kerberos Ticket Request via CLI
Status:
experimental
Description:
Detects suspicious Kerberos ticket requests via command line using System.IdentityModel.Tokens.KerberosRequestorSecurityToken class. Threat actors may use command line interfaces to request Kerberos tickets for service accounts in order to perform offline password cracking attacks commonly known as Kerberoasting or other Kerberos ticket abuse techniques like silver ticket attacks. Encoded commands will not surface the class name, so the ps_script rule covers that instead.
References:
-https://www.huntress.com/blog/gootloader-threat-detection-woff2-obfuscation
-https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1558.003/T1558.003.md#atomic-test-4---request-a-single-ticket-via-powershell
-https://learn.microsoft.com/en-us/dotnet/api/system.identitymodel.tokens.kerberosrequestorsecuritytoken?view=netframework-4.8.1
Author:
Swachchhanda Shrawan Poudel (Nextron Systems)
Date:
2025-11-18
modified:
2026-09-14
Tags:
-'attack.credential-access'
-'attack.t1558.003'
Logsource:
category: process_creation
product: windows
Detection:
selection_img:
- Image|endswith
:
- '\powershell.exe'
- '\pwsh.exe'
- OriginalFileName
:
- 'powershell.exe'
- 'pwsh.dll'
selection_cli:
CommandLine|contains
:
'System.IdentityModel.Tokens.KerberosRequestorSecurityToken'
condition
:
all of selection_*
Falsepositives:
-Legitimate command line usage by administrators or security tools
Level:
high