Splunk Enterprise Security

Golden Ticket

crisp023
New Member

Has anyone had success with setting up alerting for the Golden Ticket attack? I don't see a lot of info about it online, but I am trying to hone down a good search for it so I can set up alerts. Curious to see if anyone has any success with it.

Thanks.

0 Karma

to4kawa
Ultra Champion

jpcert report

how's this?

0 Karma
Get Updates on the Splunk Community!

New Case Study Shows the Value of Partnering with Splunk Academic Alliance

The University of Nevada, Las Vegas (UNLV) is another premier research institution helping to shape the next ...

How to Monitor Google Kubernetes Engine (GKE)

We’ve looked at how to integrate Kubernetes environments with Splunk Observability Cloud, but what about ...

Index This | How can you make 45 using only 4?

October 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...