Splunk Enterprise Security

Golden Ticket

New Member

Has anyone had success with setting up alerting for the Golden Ticket attack? I don't see a lot of info about it online, but I am trying to hone down a good search for it so I can set up alerts. Curious to see if anyone has any success with it.


0 Karma

Ultra Champion

jpcert report

how's this?

0 Karma