Splunk Enterprise

Detect Golden ticket attack using SPL?

BenzSann
Splunk Employee
Splunk Employee

Has anyone had experience to detect Golden ticket attack using SPL?

Labels (1)
0 Karma

to4kawa
Ultra Champion

ref:https://jpcertcc.github.io/ToolAnalysisResultSheet/

Why not check event details and search these?

0 Karma
Get Updates on the Splunk Community!

Cisco Catalyst Center Meets Splunk ITSI: From 'Payments Are Down' to Root Cause in ...

The Problem: When Networks and Services Don't Talk Payment systems fail at a retail location. Customers are ...

Print, Leak, Repeat: UEBA Insider Threats You Can't Ignore

Are you ready to uncover the threats hiding in plain sight? Join us for "Print, Leak, Repeat: UEBA Insider ...

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...