kevmap

TechniquesT1212 › AN0493

AN0493 Analytic 0493

Windows · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Detects adversary exploitation of authentication mechanisms or credential validation processes. Defender perspective includes forged Kerberos tickets (e.g., MS14-068), abnormal LSASS memory access, replayed authentication attempts, and unexpected crashes of authentication services. Multi-event correlation ties exploitation attempts to abnormal process creation, service instability, and suspicious authentication events.</p>
Detects
T1212 Exploitation for Credential Access
Part of
DET0174 Detection Strategy for Exploitation for Credential Access

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
WinEventLog:SecurityEventCode=4768, 4769, 4770DC0002 User Account Authentication
WinEventLog:SysmonEventCode=10DC0035 Process Access

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
MonitoredAccountsHigh-value accounts (e.g., Domain Admins) for anomalous ticket issuance or replay activity.
ReplayDetectionWindowTime window for correlating duplicate or replayed Kerberos authentications.

KEV CVEs whose mapped technique this analytic detects

CVEVendor / productState
CVE-2022-22948VMware vCenter ServerMapped
CVE-2024-53704SonicWall SonicOSMapped
CVE-2025-48927TeleMessage TM SGNLMapped
CVE-2025-48928TeleMessage TM SGNLMapped