Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Credential Access/ T1558.004

T1558.004AS-REP Roasting

T1558.004 — AS-REP Roasting is a MITRE ATT&CK technique in the Credential Access tactic. Clankerusecase tracks 6 detection use cases covering it.

Credential Access
View on the matrix → Filter Detection Library MITRE official spec ↗
6Use cases
0Articles
0Sub-techniques
1Tactic

Use cases covering this technique (6)

Disabled Kerberos Pre-Authentication Discovery With Get-ADUser ESCU actions · alerting P Disabled Kerberos Pre-Authentication Discovery With PowerView ESCU actions · alerting P Kerberos Pre-Authentication Flag Disabled in UserAccountControl ESCU actions · alerting P Kerberos Pre-Authentication Flag Disabled with PowerShell ESCU actions · alerting P Rubeus Command Line Parameters ESCU actions · alerting P Windows Process With NetExec Command Line Parameters ESCU actions · alerting P