Steal or Forge Kerberos Tickets: Ccache Files T1558.005

Tactic: Credential Access

Adversaries may attempt to steal Kerberos tickets stored in credential cache files (or ccache). These files are used for short term storage of a user's active session credentials. The ccache file is created upon user authentication and allows for access to multiple services without the user having to re-enter credentials.

Events covered

2 catalog events are tagged with this technique by at least one rule.

ProviderEventTitle
ESFexecProcess Execution
ESFopenFile Open

Authoring guide

These 4 rules share fields, values, and exclusions.

Fields filtered most (7 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
event.type3in 2, eq 1start, process_started
host.os.type3eq 3
process_name3eq 2, starts_with 1kcc, python
EventType2eq 2exec, open
process.args2eq 2, in 1-action, -kerberoast, -ticket, copy_cred_cache
CommandLine1contains 1copy_cred_cache
event.category1eq 1file

Top indicator values (21 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
event.typein
process_started
239
event.typein
start
241
process_nameeq
kcc
22
CommandLinecontains
copy_cred_cache
1
EventTypeeq
exec
1579
EventTypeeq
open
152
event.categoryeq
file
143
event.typeeq
start
11087
process.argseq
-action
12
process.argseq
-kerberoast
12
process.argseq
-ticket
12
process.argseq
askhash
12
process.argseq
asktgs
12
process.argseq
asktgt
12
process.argseq
copy_cred_cache
1
process.argseq
dump
13
process.argseq
ptt
12
process.argseq
s4u
12
process.argsin
keytab
12
process.argsin
tickets
12
process_namestarts_with
python
171

Rules under this technique

These vendors publish rules tagged with this technique.

Platform: macOS

Domain: Endpoint

Elastic 4 rules