T1550 Use Alternate Authentication Material
Adversaries may use alternate authentication material, such as password hashes, Kerberos tickets, and application access tokens, in order to move laterally within an environment and bypass normal system access controls. Authentication processes generally require a valid identity (e.g., username) along with one or more authentication factors (e.g., password, pin, physical smart card, token…
Quién la usa · con noticias en Jábega
Reglas Sigma para cazarla
- HackTool - Rubeus Executioncriticalstable · windows
- HackTool - KrbRelayUp Executionhightest · windows
- HackTool - Rubeus Execution - ScriptBlockhightest · windows
- Hacktool Rulerhightest · windows
- Successful Overpass the Hash Attempthightest · windows
- Pass the Hash Activity 2mediumstable · windows
- AWS Console GetSigninToken Potential Abusemediumtest · aws
- AWS Suspicious SAML Activitymediumtest · aws
- NTLMv1 Logon Between Client and Servermediumtest · windows
- Uncommon Outbound Kerberos Connectionmediumtest · windows
Reglas de SigmaHQ · Detection Rule License 1.1. Técnica de MITRE ATT&CK®.