Tag
high
advisory
Potential Kerberos Coercion via DNS-Based SPN Spoofing
2 rules 1 TTPAdversaries may abuse MicrosoftDNS records containing a base64-encoded blob to coerce victim systems into authenticating to attacker-controlled hosts while requesting Kerberos tickets for legitimate services, detected via directory-service access events.
Active Directory
kerberos
coercion
dns
spn
spoofing
credential-access
2r
1t
high
advisory
DNS Kerberos Coercion Attempt Detection
3 rules 3 TTPs 3 IOCsThis brief details the detection of DNS-based Kerberos coercion attacks, where adversaries inject marshaled credential structures into DNS records to spoof SPNs and redirect authentication, as seen in CVE-2025-33073, using Suricata and Sysmon event ID 22.
Fortinet edge appliances +37
kerberos
coercion
dns
cve-2025-33073
3r
3t
3i
updated