SPN Discovery
Tags
attack-pattern: | Credentials - T1589.001 Domain Accounts - T1078.002 Kerberoasting - T1558.003 Powershell - T1059.001 Python - T1059.006 Kerberoasting - T1208 Powershell - T1086 |
Common Information
Type | Value |
---|---|
UUID | 80eb0f8c-51aa-4aad-b6be-0d5eebbed861 |
Fingerprint | a3802ad30972a3e0 |
Analysis status | DONE |
Considered CTI value | 0 |
Text language | |
Published | June 4, 2018, 7 a.m. |
Added to db | Jan. 18, 2023, 10:08 p.m. |
Last updated | Nov. 17, 2024, 6:54 p.m. |
Headline | SPN Discovery |
Title | SPN Discovery |
Detected Hints/Tags/Attributes | 30/1/10 |
Source URLs
Redirection | Url | |
---|---|---|
Details | Source | https://pentestlab.blog/2018/06/04/spn-discovery/ |
URL Provider
Attributes
Details | Type | #Events | CTI | Value |
---|---|---|---|---|
Details | Domain | 22 | getuserspns.py |
|
Details | File | 4 | getuserspns.ps1 |
|
Details | File | 155 | cscript.exe |
|
Details | File | 4 | getuserspns.vbs |
|
Details | File | 2 | discover-psmssqlservers.ps1 |
|
Details | File | 1 | discover-psmsexchangeservers.ps1 |
|
Details | File | 1 | find-psserviceaccounts.ps1 |
|
Details | File | 1 | get-domainspn.ps |
|
Details | File | 20 | getuserspns.py |
|
Details | IPv4 | 97 | 10.0.0.1 |