Suspicious Kerberos Ticket Request via PowerShell CLI
Adversaries utilize the System.IdentityModel.Tokens.KerberosRequestorSecurityToken class via PowerShell command lines to conduct Kerberoasting and ticket-based credential access attacks.
Threat actors frequently leverage native administrative tools to conduct credential access operations. By executing the System.IdentityModel.Tokens.KerberosRequestorSecurityToken class directly via PowerShell or pwsh.exe command lines, an attacker can programmatically request Kerberos service tickets for arbitrary accounts. This behavior is indicative of Kerberoasting, an attack technique where service tickets are requested and subsequently exported for offline brute-force cracking to extract service account passwords. While this specific detection focuses on the explicit usage of the .NET class within command-line arguments, it is important to note that attackers frequently use obfuscation or encoded commands to bypass such visibility. Defenders should monitor for this specific pattern to identify unauthorized ticket requests originating from non-standard processes or administrative sessions.
Impact
Successful exploitation allows attackers to obtain Kerberos service tickets, which are subsequently used to perform offline password cracking. This leads to the compromise of service account credentials, potential lateral movement, and privilege escalation within Active Directory environments.
Recommendation
Deploy the provided Sigma rule to monitor for suspicious instantiation of the KerberosRequestorSecurityToken class. Review process logs associated with this activity to differentiate between legitimate administrative maintenance and malicious credential harvesting. Enable command-line logging (EID 4688) with full command-line auditing to ensure the class name is captured in logs.
Immediate actions
Deploy Sigma detection rule to monitor for KerberosRequestorSecurityToken usage
Threat Hunt
Search historical logs for processes spawning PowerShell with the specific .NET class
Data: Process command line arguments
Detection coverage 1
Suspicious Kerberos Ticket Request via CLI
highDetects suspicious Kerberos ticket requests via command line using System.IdentityModel.Tokens.KerberosRequestorSecurityToken class.
Detection queries are available on the platform. Get full rules →