diff --git a/rules/network/zeek_susp_kerberos_rc4.yml b/rules/network/zeek_susp_kerberos_rc4.yml index f9bb4d225..456f82786 100644 --- a/rules/network/zeek_susp_kerberos_rc4.yml +++ b/rules/network/zeek_susp_kerberos_rc4.yml @@ -1,6 +1,7 @@ -title: Suspicious kerberos network traffic RC4 ticket encryption +title: Kerberos Network Traffic RC4 Ticket Encryption id: 503fe26e-b5f2-4944-a126-eab405cc06e5 status: experimental +date: 2020/02/12 description: Detects kerberos TGS request using RC4 encryption which may be indicative of kerberoasting references: - https://adsecurity.org/?p=3458