Trellix published new research from the Advanced Research Center showing that Kerberoasting through misconfigured Service Principal Names can be detected at the network layer before credential theft and lateral movement.
Public source
Publisher name
Public post
The most dangerous identity attack may be the one your identity tools never see. Active Directory is still the heart of most enterprise environments and attackers keep f…
Company
Trellix
Mission-critical security for intelligence-led cyber resilience
- Industry
- Computer and Network Security
- Location
- Plano, US
- Company size
- 1,001–5,000 employees
About Trellix
Trellix is a global cybersecurity company delivering intelligence-led cyber resilience for security-conscious organizations at any stage of their journey. Transforming over 30 years of threat intelligence into high-fidelity detections and automating AI-driven detection and response across cloud, on-premises, air-gapped, and operational technology environments, Trellix helps customers adapt to the constantly evolving threat landscape. More at https://trellix.com.
See moreLatest activity
Latest activity from Trellix
49 signals
Research & Knowledge
Trellix launched the newly released Trellix SecondSight Threat Hunting Report, which investigates the gray space between routine activity and confirmed attacks by combining telemetry from endpoint, network, and email sources with human threat hunters.
Research & Knowledge
Trellix published an article detailing how attackers exploit ordinary user accounts with assigned SPNs to request encrypted tickets and crack them offline without triggering lockout alarms.
Presence & Recognition
Trellix intelligence experts are unpacking how threat actors are deploying AI as active attack participants on September 22.
Discover more
Similar signals
Similar public activity from other companies.
Research & Knowledge
Trellix
Trellix published a research blog detailing the complete kill chain for attackers hijacking Active Directory, including domain-wide user SPN enumeration, RC4 TGS requests, memory dumps, offline cracking, and obfuscation techniques.
Research & Knowledge
Netwrix Corporation
Netwrix Corporation published the Netwrix Threat Lab Quarterly research digest, translating original identity, AD, and AI threat research into practical fixes for teams defending against them.
Research & Knowledge
Iterasec
Iterasec published a new article on Active Directory attack paths focusing on low-privileged footholds moving through the environment toward Domain Admin.
Research & Knowledge
ThreatLight
ThreatLight researchers outlined a large-scale data theft and extortion campaign abusing SaaS accounts, with Microsoft 365 environments and executive roles frequently in scope.
Research & Knowledge
Cyderes