Exact rules name this CVE ID. Product rules name an affected product in their title. Related rules cover techniques used by actors who exploited this CVE. Showing the most relevant matches; the complete related set is on the full drill-down.
producthighSuspicious DNS Query Indicating Kerberos Coercion via DNS Object SPN Spoofing - Network
producthighSuspicious Kerberos Ticket Request via PowerShell Script - ScriptBlock
producthighSuspicious DNS Query Indicating Kerberos Coercion via DNS Object SPN Spoofing
producthighAttempts of Kerberos Coercion Via DNS SPN Spoofing
producthighSuspicious Kerberos Ticket Request via CLI
producthighPotential Kerberos Coercion by Spoofing SPNs via DNS Manipulation
Show all 16 top matches
producthighPetitPotam Suspicious Kerberos TGT Request
producthighKerberos Manipulation
productcriticalLinux Reverse Shell Indicator
producthighCommunication To LocaltoNet Tunneling Service Initiated - Linux
producthighPotentially Suspicious Malware Callback Communication - Linux
producthighLinux Crypto Mining Pool Connections
producthighCommunication To Ngrok Tunneling Service - Linux
producthighLinux Crypto Mining Indicators
producthighShell Execution GCC - Linux
producthighShell Execution via Rsync - Linux