updating analytic story name

This commit is contained in:
mvelazco
2022-04-28 18:10:40 -04:00
parent 8a8581d959
commit fce3ecbfa6
5 changed files with 23 additions and 21 deletions
@@ -21,7 +21,7 @@ references:
tags:
analytic_story:
- Active Directory Kerberos Attacks
- KrbRelayUp
- Local Privilege Escalation With KrbRelayUp
asset_type: Endpoint
cis20:
- CIS 3
@@ -19,7 +19,7 @@ references:
tags:
analytic_story:
- Active Directory Kerberos Attacks
- KrbRelayUp
- Local Privilege Escalation With KrbRelayUp
asset_type: Endpoint
cis20:
- CIS 3
@@ -23,7 +23,7 @@ references:
tags:
analytic_story:
- Active Directory Kerberos Attacks
- KrbRelayUp
- Local Privilege Escalation With KrbRelayUp
asset_type: Endpoint
cis20:
- CIS 3
-18
View File
@@ -1,18 +0,0 @@
name: KrbRelayUp
id: 765790f0-2f8f-4048-8321-fd1928ec2546
version: 1
date: '2022-04-28'
author: Michael Haag, Splunk
description: KrbRelayUp is a universal no-fix local privilege escalation in Windows domain environments where LDAP signing is not enforced (the default settings).
narrative: UPDATE_NARRATIVE
references:
- https://github.com/Dec0ne/KrbRelayUp
tags:
analytic_story: KrbRelayUp
category:
- Privilege Escalation
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
usecase: Advanced Threat Detection
@@ -0,0 +1,20 @@
name: Local Privilege Escalation With KrbRelayUp
id: 765790f0-2f8f-4048-8321-fd1928ec2546
version: 1
date: '2022-04-28'
author: Michael Haag, Mauricio Velazco, Splunk
description: KrbRelayUp is a tool that allows local privilege escalation from low-priviliged domain user to local system on domain-joined computers.
narrative: UPDATE_NARRATIVE
references:
- https://github.com/Dec0ne/KrbRelayUp
- https://gist.github.com/tothi/bf6c59d6de5d0c9710f23dae5750c4b9
- https://googleprojectzero.blogspot.com/2021/10/using-kerberos-for-authentication-relay.html
tags:
analytic_story: Local Privilege Escalation With KrbRelayUp
category:
- Privilege Escalation
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
usecase: Advanced Threat Detection