kevmap

TechniquesT1558 › AN1444

AN1444 Analytic 1444

Linux · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Detects suspicious access to SSSD secrets database and Kerberos key material indicating ticket theft or replay attempts. Correlates anomalous file access with unusual Kerberos service ticket requests.</p>
Detects
T1558 Steal or Forge Kerberos Tickets
Part of
DET0522 Detect Kerberos Ticket Theft or Forgery (T1558)

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
auditd:SYSCALLAccess to /var/lib/sss/secrets/secrets.ldb or .secrets.mkeyDC0055 File Access
linux:syslogUnusual kinit or klist activityDC0084 Active Directory Credential Request

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
SecretsAccessThresholdAlert threshold for frequency of access to Kerberos secrets files.
UnusualServiceAccountsBaseline accounts normally performing Kerberos requests; anomalies flagged.

KEV CVEs whose mapped technique this analytic detects

CVEVendor / productState
CVE-2024-13159Ivanti Endpoint Manager (EPM)Mapped
CVE-2024-13160Ivanti Endpoint Manager (EPM)Mapped
CVE-2024-13161Ivanti Endpoint Manager (EPM)Mapped