Attack Tool(s): Kerbrute, NetExec, Net Use, lolbins
- Kerbrute: https://github.com/ropnop/kerbrute
- NetExec: https://github.com/Pennyw0rth/NetExec
- Net Use: Native Windows command.
- lolbins: https://lolbas-project.github.io
Detection Link(s):
- User and Entity Behavior Analytics (UEBA)
- Active Defense and Cyber Deception
- Security Information and Event Management (SIEM) Log Analysis
- Endpoint Security Protection Analysis
Helpful Blogs (BHIS):
- “Webcast: Attack Tactics 5 – Zero to Hero” – https://www.blackhillsinfosec.com/webcast-attack-tactics-5-zero-to-hero-attack – Kerbrute usage.
