Kerberoasted

Kerberoasted is a blue team lab that falls under the Threat Hunting category and will cover the following subjects: Splunk, ELK, Credential Access, Discovery.

Learning Objectives

Detect, analyze, and respond to Kerberoasting attacks by investigating Kerberos logs, identifying compromised accounts, and uncovering attacker persistence methods.

Categories: Threat Hunting.

MITRE ATT&CK Tactics: Credential Access, Discovery.

Tools: Splunk, ELK.

Difficulty: medium.