Added reference to Kerberos RC4 rule

This commit is contained in:
Thomas Patzke
2018-03-25 23:18:22 +02:00
parent dacc6ae3d3
commit f68af2a5da
@@ -2,7 +2,8 @@ title: Suspicious Kerberos RC4 Ticket Encryption
status: experimental
references:
- https://adsecurity.org/?p=3458
description: Detects logons using RC4 encryption type
- https://www.trimarcsecurity.com/single-post/TrimarcResearch/Detecting-Kerberoasting-Activity
description: Detects service ticket requests using RC4 encryption type
logsource:
product: windows
service: security