tag

kerberos

11 indexed skills · max 10 per page

skills (11)

detecting-pass-the-ticket-attacks

mukul975/Anthropic-Cybersecurity-Skills · detecting-pass-the-ticket-attacks

0

Detect Kerberos Pass-the-Ticket (PtT) attacks by analyzing Windows Event IDs 4768, 4769, and 4771 for anomalous ticket usage patterns in Splunk and Elastic SIEM

detecting-dcsync-attack-in-active-directory

mukul975/Anthropic-Cybersecurity-Skills · detecting-dcsync-attack-in-active-directory

0

Detect DCSync attacks where adversaries abuse Active Directory replication privileges to extract password hashes by monitoring for non-domain-controller accounts requesting directory replication via DsGetNCChanges.

performing-active-directory-vulnerability-assessment

mukul975/Anthropic-Cybersecurity-Skills · performing-active-directory-vulnerability-assessment

0

Assess Active Directory security posture using PingCastle, BloodHound, and Purple Knight to identify misconfigurations, privilege escalation paths, and attack vectors.

performing-active-directory-forest-trust-attack

mukul975/Anthropic-Cybersecurity-Skills · performing-active-directory-forest-trust-attack

0

Enumerate and audit Active Directory forest trust relationships using impacket for SID filtering analysis, trust key extraction, cross-forest SID history abuse detection, and inter-realm Kerberos ticket assessment.

exploiting-constrained-delegation-abuse

mukul975/Anthropic-Cybersecurity-Skills · exploiting-constrained-delegation-abuse

0

Exploit Kerberos Constrained Delegation misconfigurations in Active Directory to impersonate privileged users via S4U2self and S4U2proxy extensions for lateral movement and privilege escalation.

detecting-golden-ticket-attacks-in-kerberos-logs

mukul975/Anthropic-Cybersecurity-Skills · detecting-golden-ticket-attacks-in-kerberos-logs

0

Detect Golden Ticket attacks in Active Directory by analyzing Kerberos TGT anomalies including mismatched encryption types, impossible ticket lifetimes, non-existent accounts, and forged PAC signatures in domain controller event logs.

performing-active-directory-compromise-investigation

mukul975/Anthropic-Cybersecurity-Skills · performing-active-directory-compromise-investigation

0

Investigate Active Directory compromise by analyzing authentication logs, replication metadata, Group Policy changes, and Kerberos ticket anomalies to identify attacker persistence and lateral movement paths.

exploiting-kerberoasting-with-impacket

mukul975/Anthropic-Cybersecurity-Skills · exploiting-kerberoasting-with-impacket

0

Perform Kerberoasting attacks using Impacket's GetUserSPNs to extract and crack Kerberos TGS tickets for Active Directory service accounts.

conducting-pass-the-ticket-attack

mukul975/Anthropic-Cybersecurity-Skills · conducting-pass-the-ticket-attack

0

Pass-the-Ticket (PtT) is a lateral movement technique that uses stolen Kerberos tickets (TGT or TGS) to authenticate to services without knowing the user's password. By extracting Kerberos tickets fro

detecting-kerberoasting-attacks

mukul975/Anthropic-Cybersecurity-Skills · detecting-kerberoasting-attacks

0

Detect Kerberoasting attacks by monitoring for anomalous Kerberos TGS requests targeting service accounts with SPNs for offline password cracking.

prevpage 1 / 2next