Hunting Kerberos Attacks: Golden Tickets, Silver Tickets, and AS-REP Roasting
A deep dive into hunting Golden Ticket, Silver Ticket, and AS-REP roasting attacks against Kerberos authentication in Active Directory.
A deep dive into hunting Golden Ticket, Silver Ticket, and AS-REP roasting attacks against Kerberos authentication in Active Directory.
A complete guide to detecting the methods attackers use to steal credentials from Windows systems, from LSASS dumping to Kerberoasting.
A deep dive into detecting process injection and hollowing, the evasion technique underpinning much of modern malicious tradecraft.
Why defense evasion is the hardest ATT&CK tactic to detect, and how hunters should approach techniques built specifically to defeat them.
How to detect the techniques attackers use to escalate from a standard user account to administrator or SYSTEM-level access.
A focused, practical deep dive into hunting the three most common Windows persistence locations attackers actually rely on.
A complete guide to hunting the persistence mechanisms attackers rely on to maintain access across reboots, credential changes, and time.
A focused, practical guide to hunting PowerShell abuse and living-off-the-land binaries, the execution techniques attackers rely on most.
A hunter's guide to detecting execution techniques used after initial access, from scripting interpreters to scheduled task abuse.
Detecting initial access through supply chain compromise and abuse of trusted third-party access, the hardest foothold to hunt for.