T1558Steal or Forge Kerberos Tickets
T1558 — Steal or Forge Kerberos Tickets is a MITRE ATT&CK technique in the Credential Access tactic. Clankerusecase tracks 6 detection use cases covering it and 4 threat-intel articles citing it.
Credential Access
6Use cases
4Articles
5Sub-techniques
1Tactic
Sub-techniques (5)
Use cases covering this technique (6)
Windows Computer Account Created by Computer Account Windows Computer Account Requesting Kerberos Ticket Windows Computer Account With SPN Windows Domain Admin Impersonation Indicator Windows Kerberos Local Successful Logon Windows Steal or Forge Kerberos Tickets KlistArticles citing this technique (4)
crit Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller art-97