CAPEC 652 Use of Known Kerberos Credentials

Draft Standard Medium Risk
Severity High

Description

An adversary obtains (i.e. steals or purchases) legitimate Kerberos credentials (e.g. Kerberos service account userID/password or Kerberos Tickets) with the goal of achieving authenticated access to additional systems, applications, or services within the domain.

Attack Execution Flow

5

Mitigations

7

Consequences

Indicators

5

Relationships

Related ATT&CK Techniques

1

Resources Required

1