Tag
medium
advisory
Detection of Forced Authentication via SMB Named Pipes
1 rule 1 TTPAdversaries leverage Linux-based systems to coerce Windows hosts into authenticating against attacker-controlled resources via SMB named pipes, facilitating NTLM hash capture and SMB relay attacks.
Active Directory +1
credential-access
active-directory
smb
linux
windows
coercion
1r
1t
updated
high
advisory
Potential Kerberos Coercion via DNS-Based SPN Spoofing
2 rules 1 TTPAdversaries may abuse MicrosoftDNS records containing a base64-encoded blob to coerce victim systems into authenticating to attacker-controlled hosts while requesting Kerberos tickets for legitimate services, detected via directory-service access events.
Active Directory
kerberos
coercion
dns
spn
spoofing
credential-access
2r
1t
high
advisory
DNS Kerberos Coercion Attempt Detection
3 rules 3 TTPs 4 CVEs 4 IOCsThis brief details the detection of DNS-based Kerberos coercion attacks, where adversaries inject marshaled credential structures into DNS records to spoof SPNs and redirect authentication, as seen in CVE-2025-33073, using Suricata and Sysmon event ID 22.
PoC
Fortinet edge appliances +38
kerberos
coercion
dns
cve-2025-33073
3r
3t
4c
4i
updated