Skip to content
Threat Feed
high advisory

Suspicious Kerberos Ticket Request via PowerShell CLI

Adversaries utilize the System.IdentityModel.Tokens.KerberosRequestorSecurityToken class via PowerShell command lines to conduct Kerberoasting and ticket-based credential access attacks.

Threat actors frequently leverage native administrative tools to conduct credential access operations. By executing the System.IdentityModel.Tokens.KerberosRequestorSecurityToken class directly via PowerShell or pwsh.exe command lines, an attacker can programmatically request Kerberos service tickets for arbitrary accounts. This behavior is indicative of Kerberoasting, an attack technique where service tickets are requested and subsequently exported for offline brute-force cracking to extract service account passwords. While this specific detection focuses on the explicit usage of the .NET class within command-line arguments, it is important to note that attackers frequently use obfuscation or encoded commands to bypass such visibility. Defenders should monitor for this specific pattern to identify unauthorized ticket requests originating from non-standard processes or administrative sessions.

Impact

Successful exploitation allows attackers to obtain Kerberos service tickets, which are subsequently used to perform offline password cracking. This leads to the compromise of service account credentials, potential lateral movement, and privilege escalation within Active Directory environments.

Recommendation

Deploy the provided Sigma rule to monitor for suspicious instantiation of the KerberosRequestorSecurityToken class. Review process logs associated with this activity to differentiate between legitimate administrative maintenance and malicious credential harvesting. Enable command-line logging (EID 4688) with full command-line auditing to ensure the class name is captured in logs.


Immediate actions

Deploy Sigma detection rule to monitor for KerberosRequestorSecurityToken usage

Detection Engineering 48h

Threat Hunt

Search historical logs for processes spawning PowerShell with the specific .NET class

T1558.003 high high confidence hunt now

Data: Process command line arguments

Detection coverage 1

Suspicious Kerberos Ticket Request via CLI

high

Detects suspicious Kerberos ticket requests via command line using System.IdentityModel.Tokens.KerberosRequestorSecurityToken class.

sigma tactics: credential-access techniques: T1558.003 sources: process_creation, windows

Detection queries are available on the platform. Get full rules →