Vendor: Apple

June 14, 2023 · View on GitHub

Product: macOS

Use-Case: Lateral Movement

RulesModelsMITRE ATT&CK® TTPsEvent TypesParsers
10211
Event TypeRulesModels
local-logonT1550.003 - Use Alternate Authentication Material: Pass the Ticket
EXPERT-PENTEST-DOMAINS: Possible credentials theft attack detected

T1558 - Steal or Forge Kerberos Tickets
EXPERT-PENTEST-DOMAINS: Possible credentials theft attack detected