T1550 Use Alternate Authentication Material
Adversaries may use alternate authentication material, such as password hashes, Kerberos tickets, and application access tokens, in order to move laterally within an environment and bypass normal system access controls. Authentication processes generally require a valid identity (e.g., username) along with one or more authentication factors (e.g., password, pin, physical smart card, token…
Who uses it · with stories on Jábega
Sigma rules to hunt it
- HackTool - Rubeus Executioncriticalstable · windows
- HackTool - KrbRelayUp Executionhightest · windows
- HackTool - Rubeus Execution - ScriptBlockhightest · windows
- Hacktool Rulerhightest · windows
- Successful Overpass the Hash Attempthightest · windows
- Pass the Hash Activity 2mediumstable · windows
- AWS Console GetSigninToken Potential Abusemediumtest · aws
- AWS Suspicious SAML Activitymediumtest · aws
- NTLMv1 Logon Between Client and Servermediumtest · windows
- Uncommon Outbound Kerberos Connectionmediumtest · windows
Rules from SigmaHQ · Detection Rule License 1.1. Technique from MITRE ATT&CK®.