Back to category

Week 1

Hunt Credential Theft and Kerberoasting in a Legacy Active Directory

Beginner
Threat Hunter
SOC Analyst (L3)
Detection Engineer
MITRE ATT&CK
NIST SP 800-137
MITRE D3FEND
Sigma
NIST CSF 2.0
NIST SP 800-207 (Zero Trust)
Threat Hunting
MITRE ATT&CK Mapping
Kerberos Attack Detection
Detection Engineering
gMSA Transition

Client Background

Heartland Mutual Insurance is a 1,100-employee regional insurer running a single-forest, single-domain Windows Server 2012 R2 Active Directory that also supports a legacy claims-issuance app and an on-prem SQL-driven data warehouse. The company has no dedicated detection engineering capacity and contracts after-hours triage to an external SOC.

Business Environment

Most staff are hybrid-remote. Both domain controllers are Windows Server 2012 R2 (scheduled for 2025-2026 migration to 2022). EDR is deployed on endpoints; Sysmon and Windows Event Forwarding feed the SIEM. RC4-HMAC TGS requests have never been alerted on.

Security Incident

A junior SOC analyst dismissed a late-Friday EDR alert on workstation WK-FINANCE-008 as 'expected installer activity'. On Monday, CISA advisory AA24-290A prompted a proactive hunt for credential-theft TTPs across the domain. Historically the firm has under-monitored Kerberos abuse and LSASS access events.

Scope

This engagement covers domain controllers DC01 and DC02, member servers FS01 and FS02, and the 220 member workstations. Cloud and SaaS identity are out of scope.

Objectives

  • Develop and execute a hypothesis-driven hunt for credential theft TTPs (T1003 OS Credential Dumping and T1558 Steal or Forge Kerberos Tickets)
  • Differentiate legitimate service-ticket requests from Kerberoasting patterns in DC event logs and Sysmon
  • Produce an actionable work-plan for remediation and detection-engineering follow-up
  • Prioritize the gMSA transition and reference modern endpoint protections (Credential Guard, PPL) as the 2026 standard Kerberoasting mitigation rather than legacy lockout/rotation alone.

Required Deliverables

Hunt hypothesis plus ABLE findings (Analyzed, Behavior, Location, Evidence) report
List of confirmed service accounts vulnerable to Kerberoasting with remediation recommendations
Detection content recommendations (Sigma/KQL) for at least three techniques
3 hrs estimated