Abstract
The paper focus is the detection of Kerberoasting attack in Active Directory environment. The purpose of the attack is to extract service accounts’ passwords without need for any special user access rights or privilege escalation, which makes it suitable for initial phases of network compromise and further pivot for more interesting accounts. The main goal of the paper is to discuss the monitoring possibilities, setting up detection rules built on top of native Active Directory auditing capabilities, including possible ways to minimize false positive alerts.
Author supplied keywords
Cite
CITATION STYLE
Kotlaba, L., Buchovecká, S., & Lórencz, R. (2020). Active Directory Kerberoasting Attack: Monitoring and Detection Techniques. In International Conference on Information Systems Security and Privacy (pp. 432–439). Science and Technology Publications, Lda. https://doi.org/10.5220/0008955004320439
Register to see more suggestions
Mendeley helps you to discover research relevant for your work.