Vedran Dojčinović
← MITRE ATT&CK

T1558.003

1post covers this technique, publishing 1 rule.

attack.mitre.org/techniques/T1558/003 ↗

Detecting Kerberoasting with Wazuh

The rule is six lines of XML. The part that actually mattered was a query I ran before writing any of it.