Microsoft Security Operations AnalystMitigate threats using Microsoft Defender XDRHard

A security team is analyzing a series of alerts generated by Microsoft Defender for Identity related to a potential 'Golden Ticket' attack. They suspect that a threat actor has successfully compromised the Kerberos Ticket Granting Ticket (TGT) of a domain controller. To confirm this and understand the full impact, the team needs to perform a detailed forensic investigation. Which specific log source, critical for detecting and analyzing Kerberos-related attacks like Golden Ticket, should the team focus on within their SIEM or Advanced Hunting queries?

  1. AWindows Event Log: Security (Event ID 4769 - A Kerberos service ticket was requested)
  2. BWindows Event Log: System (Event ID 7036 - Service Control Manager)
  3. CWindows Event Log: Application (Event ID 1000 - Application Error)
  4. DWindows Event Log: Security (Event ID 4624 - Logon)
Show answer & explanation

Correct answer: A. Windows Event Log: Security (Event ID 4769 - A Kerberos service ticket was requested)

Event ID 4769, 'A Kerberos service ticket was requested', is crucial for detecting Golden Ticket attacks. While Golden Tickets forge TGTs, the subsequent requests for service tickets using these forged TGTs will generate 4769 events, often with anomalies like unusual client names or lack of pre-authentication data, which are key indicators of compromise.

Why the other options are wrong

  • B. Event ID 7036 (Service Control Manager) is related to service status changes and is irrelevant to Kerberos ticket attacks.
  • C. Event ID 1000 (Application Error) is too generic and not specific to Kerberos authentication or Golden Ticket attacks.
  • D. Event ID 4624 (Logon) indicates successful logons but doesn't provide the specific Kerberos service ticket details needed to detect Golden Ticket attacks.

Kerberos Event ID 4769

A Windows Security Event Log ID that records when a Kerberos service ticket (TGS ticket) is requested. It's critical for detecting Kerberos-based attacks like Golden Ticket.

  • Logs service ticket requests after TGT acquisition.
  • Contains details about the client, server, and ticket options.
  • Anomalies in these logs can indicate forged TGTs (Golden Tickets).

Memory trick: To find the Golden Ticket, look for unusual requests for service tickets.

More Mitigate threats using Microsoft Defender XDR questions