Windows 10: Suspected identity theft pass-the-ticket we can see kerberos ticket from one server and...

Discus and support Suspected identity theft pass-the-ticket we can see kerberos ticket from one server and... in Windows 10 Software and Apps to solve the problem; Suspected identity theft pass-the-ticket we can see kerberos ticket from one server and used it on 2 computers is this can be possible as we have... Discussion in 'Windows 10 Software and Apps' started by Khaja Fazalulla, Sep 19, 2023.

  1. Suspected identity theft pass-the-ticket we can see kerberos ticket from one server and...


    Suspected identity theft pass-the-ticket we can see kerberos ticket from one server and used it on 2 computers is this can be possible as we have received the incidents from defender for identity

    :)
     
    Khaja Fazalulla, Sep 19, 2023
    #1

  2. Check for Valid Kerberos Ticket

    Hello everyone,

    I'm looking to be able to generate a command klist to check and see if a kerberos ticket is valid.

    If the ticket is valid return 1 if a ticket is invalid return something a 0.

    We are moving from Linux to Windows for this process but I have yet to find any documentation regarding how you would do this.

    I would believe that a sample or model would be everywhere.

    Regardless does anyone have some suggestions on getting this accomplished.

    Regards,

    Jonathan
     
    Marshall_99, Sep 19, 2023
    #2
  3. Sali S Win User
    Question about ciphers used in Kerberos ticket

    Hi,

    From time to time I would see monitoring system alerting on requests using RC4 cipher in Kerberos ticket:

    Client server (client1) : Windows 2008 R2

    Domain controller (dc1) : Windows 2016

    Following is a sample capture from the monitoring system:

    client : *** Email address is removed for privacy ***

    dest_server: dc1

    dest_port: 88

    auth_ticket_cipher : aes256-cts-hmac-sha1-96

    auth_ticket_ciphertext - xxxxxx

    request_type : TGS

    new_ticket_cipher: rc4-hmac

    new_ticket_ciphertext: xxxxxxx

    I'm wondering what determines the encryption cipher to to be used in a Kerberos ticket request? I've heard about Kerberoasting so I would like to know how to identify if such a request is normal or not, thanks.

    Regards,
     
    Sali S, Sep 19, 2023
    #3
  4. Sali S Win User

    Suspected identity theft pass-the-ticket we can see kerberos ticket from one server and...

    Question about ciphers used in Kerberos ticket

    Thanks I've created the ticket in the Tech forum.
     
    Sali S, Sep 19, 2023
    #4
Thema:

Suspected identity theft pass-the-ticket we can see kerberos ticket from one server and...

Loading...
  1. Suspected identity theft pass-the-ticket we can see kerberos ticket from one server and... - Similar Threads - Suspected identity theft

  2. Mass amount of pass the ticket

    in Windows 10 Gaming
    Mass amount of pass the ticket: Hi!We have been detecting the massive ammount of pass the ticket activity in our AD. There is an alarm generated in ad monitoring system every minute. No technique or process created or used that would indicate that the attack is pass the ticketno mimikatze or rubeus. I would...
  3. Mass amount of pass the ticket

    in Windows 10 Software and Apps
    Mass amount of pass the ticket: Hi!We have been detecting the massive ammount of pass the ticket activity in our AD. There is an alarm generated in ad monitoring system every minute. No technique or process created or used that would indicate that the attack is pass the ticketno mimikatze or rubeus. I would...
  4. help with ticket

    in Windows 10 Gaming
    help with ticket: Hello: I had a support person help the other day but I need to follow up and complete this: ticket #7066901076 https://answers.microsoft.com/en-us/windows/forum/all/help-with-ticket/c45adc28-a44b-4ec3-8b8e-6a6a82cf58cc
  5. help with ticket

    in Windows 10 Software and Apps
    help with ticket: Hello: I had a support person help the other day but I need to follow up and complete this: ticket #7066901076 https://answers.microsoft.com/en-us/windows/forum/all/help-with-ticket/c45adc28-a44b-4ec3-8b8e-6a6a82cf58cc
  6. Identity theft

    in Windows 10 Software and Apps
    Identity theft: Hello please advise how I can have a Microsoft email address closed down, it belongs to someone who is attempting identity theft on me. they have created an email address that is similar to mine, but not mine, and they have been replacing my email address across multiple...
  7. Ticket

    in Windows 10 Gaming
    Ticket: I've had this account forever. I went to sign into it and it's erased. Nothing's there. I just set on the phone with an agen for over 30 mins and got no where she didn't even read the screen which like her only JOB AND IM PRETTY SURE SHE WAS ANSWERING multi calls cause she...
  8. Ticket

    in Windows 10 Software and Apps
    Ticket: I've had this account forever. I went to sign into it and it's erased. Nothing's there. I just set on the phone with an agen for over 30 mins and got no where she didn't even read the screen which like her only JOB AND IM PRETTY SURE SHE WAS ANSWERING multi calls cause she...
  9. Generate kerberos ticket with secure32.dll fails after disabling RC4_HMAC_MD5

    in Windows 10 Software and Apps
    Generate kerberos ticket with secure32.dll fails after disabling RC4_HMAC_MD5: Hi all,We use the secure32.dll to generate a kerberos ticket on a windows 2019 Server.After disabling the RC4 security advisory 2868725 the InitializeSecurityContext fails with error 2146892990How to work around this ?Any help is highly appreciated.TIA Dan...
  10. Suspected identity theft pass-the-ticket we can see kerberos ticket from one server and...

    in Windows 10 Gaming
    Suspected identity theft pass-the-ticket we can see kerberos ticket from one server and...: Suspected identity theft pass-the-ticket we can see kerberos ticket from one server and used it on 2 computers is this can be possible as we have received the incidents from defender for identity...