Trellix published an article detailing how attackers exploit ordinary user accounts with assigned SPNs to request encrypted tickets and crack them offline without triggering lockout alarms.
Public source
Publisher name
Public post
Is your Active Directory monitoring leaving a blind spot for Kerberoasting? Attackers are moving away from traditional service accounts—instead, they're exploiting ordin…
Company
Trellix
Mission-critical security for intelligence-led cyber resilience
- Industry
- Computer and Network Security
- Location
- Plano, US
- Company size
- 1,001–5,000 employees
About Trellix
Trellix is a global cybersecurity company delivering intelligence-led cyber resilience for security-conscious organizations at any stage of their journey. Transforming over 30 years of threat intelligence into high-fidelity detections and automating AI-driven detection and response across cloud, on-premises, air-gapped, and operational technology environments, Trellix helps customers adapt to the constantly evolving threat landscape. More at https://trellix.com.
See moreLatest activity
Latest activity from Trellix
49 signals
Research & Knowledge
Trellix launched the newly released Trellix SecondSight Threat Hunting Report, which investigates the gray space between routine activity and confirmed attacks by combining telemetry from endpoint, network, and email sources with human threat hunters.
Presence & Recognition
Trellix intelligence experts are unpacking how threat actors are deploying AI as active attack participants on September 22.
Products & Services
Trellix published a new book titled AI Generalist Engineer—From AI User to AI Builder, covering Generative AI, LLMs, AI Agents, application development, enterprise integration, automation, cloud, architecture, and governance.
Discover more
Similar signals
Similar public activity from other companies.
Research & Knowledge
Trellix
Trellix published an article detailing how attackers exploit ordinary user accounts with assigned SPNs to request encrypted tickets and crack them offline without triggering lockout alarms.
Research & Knowledge
Iterasec
Iterasec published a new article on Active Directory attack paths focusing on low-privileged footholds moving through the environment toward Domain Admin.
Research & Knowledge
Netwrix Corporation
Netwrix Corporation published the first issue of Threat Lab Quarterly, including a PowerShell script for remediating stale SPNs, ghost SPNs, and SPNs pointing to non-existent hosts.
Research & Knowledge
wizlynx group
wizlynx group published a blog post breaking down how service principal attack paths form and what security leaders should be asking their teams instead.
Research & Knowledge
ThreatLight