Active Directory Kerberoasting Attack: Monitoring and Detection Techniques

1Citations
Citations of this article
19Readers
Mendeley users who have this article in their library.
Get full text

Abstract

The paper focus is the detection of Kerberoasting attack in Active Directory environment. The purpose of the attack is to extract service accounts’ passwords without need for any special user access rights or privilege escalation, which makes it suitable for initial phases of network compromise and further pivot for more interesting accounts. The main goal of the paper is to discuss the monitoring possibilities, setting up detection rules built on top of native Active Directory auditing capabilities, including possible ways to minimize false positive alerts.

Cite

CITATION STYLE

APA

Kotlaba, L., Buchovecká, S., & Lórencz, R. (2020). Active Directory Kerberoasting Attack: Monitoring and Detection Techniques. In International Conference on Information Systems Security and Privacy (pp. 432–439). Science and Technology Publications, Lda. https://doi.org/10.5220/0008955004320439

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free