Tag
medium
advisory
Kerberos Pre-authentication Disabled for User Account
3 rules 4 TTPsDetection of Kerberos pre-authentication being disabled for a user account, potentially leading to AS-REP roasting and offline password cracking by attackers with GenericWrite or GenericAll rights over the account.
Active Directory
kerberos
credential-access
as-rep-roasting
active-directory
windows
3r
4t
high
advisory
Kerberos Pre-Authentication Disabled for User Account
2 rules 1 TTPDetection of the Kerberos pre-authentication flag being disabled in a user account via Windows Security Event 4738, enabling AS-REP Roasting attacks for offline password brute-forcing.
Active Directory
kerberos
as-rep roasting
credential-access
2r
1t