What problem does it solve?
Service accounts are high-value targets because they hold elevated privileges and their misuse blends into normal background activity. This Skill gives threat hunters a structured workflow to detect interactive logons, Kerberoasting precursors, privilege escalation, and lateral movement involving service accounts before attackers establish persistence.
Core Features & Use Cases
- Anomalous Logon Detection: Hunt Windows Event 4624 Type 2 and Type 10 logons for service accounts that should only show Type 3 or Type 5 activity.
- Kerberoasting Detection: Identify T1558.003 via 4769 TGS requests with RC4 ticket encryption (0x17) against service account SPNs.
- Baseline Deviation Analysis: Compare each service account's source hosts and activity hours against a 30-day baseline to surface lateral movement.
- Use Case: A SOC analyst investigates a backup service account that suddenly authenticates to a domain controller off-hours; the Skill guides hypothesis formation, SIEM/EDR queries, validation with Atomic T1558.003 tests, and structured reporting.
Quick Start
Hunt for service accounts showing interactive or RDP logons in the last 30 days and flag any that deviate from their baseline source hosts.