Steal or Forge Kerberos Tickets: Ccache Files T1558.005
Tactic: Credential Access
Adversaries may attempt to steal Kerberos tickets stored in credential cache files (or ccache). These files are used for short term storage of a user's active session credentials. The ccache file is created upon user authentication and allows for access to multiple services without the user having to re-enter credentials.
Events covered
2 catalog events are tagged with this technique by at least one rule.
| Provider | Event | Title |
|---|---|---|
| ESF | exec | Process Execution |
| ESF | open | File Open |
Authoring guide
These 4 rules share fields, values, and exclusions.
Fields filtered most (7 distinct)
These fields appear most often in rule filters.
Top indicator values (21 distinct)
These values appear most often in rule predicates.
Rules under this technique
These vendors publish rules tagged with this technique.
Platform: macOS
Domain: Endpoint