Week 1
Hunt Credential Theft and Kerberoasting in a Legacy Active Directory
Client Background
Heartland Mutual Insurance is a 1,100-employee regional insurer running a single-forest, single-domain Windows Server 2012 R2 Active Directory that also supports a legacy claims-issuance app and an on-prem SQL-driven data warehouse. The company has no dedicated detection engineering capacity and contracts after-hours triage to an external SOC.
Business Environment
Most staff are hybrid-remote. Both domain controllers are Windows Server 2012 R2 (scheduled for 2025-2026 migration to 2022). EDR is deployed on endpoints; Sysmon and Windows Event Forwarding feed the SIEM. RC4-HMAC TGS requests have never been alerted on.
Security Incident
A junior SOC analyst dismissed a late-Friday EDR alert on workstation WK-FINANCE-008 as 'expected installer activity'. On Monday, CISA advisory AA24-290A prompted a proactive hunt for credential-theft TTPs across the domain. Historically the firm has under-monitored Kerberos abuse and LSASS access events.
Scope
This engagement covers domain controllers DC01 and DC02, member servers FS01 and FS02, and the 220 member workstations. Cloud and SaaS identity are out of scope.
Objectives
- Develop and execute a hypothesis-driven hunt for credential theft TTPs (T1003 OS Credential Dumping and T1558 Steal or Forge Kerberos Tickets)
- Differentiate legitimate service-ticket requests from Kerberoasting patterns in DC event logs and Sysmon
- Produce an actionable work-plan for remediation and detection-engineering follow-up
- Prioritize the gMSA transition and reference modern endpoint protections (Credential Guard, PPL) as the 2026 standard Kerberoasting mitigation rather than legacy lockout/rotation alone.
Required Deliverables