LoFP LoFP / t1558

t1558

TitleTags
administration activity
false positives are possible, filtering may be required to restrict to workstations vs domain controllers. filter as needed.
false positives may trigger the detections certain scenarios like directory service delays or out of date lookups. filter as needed.
http traffic on a non standard port. verify that the destination ip address is not related to a domain controller.
it is possible false positives will be present based on third party applications. filtering may be needed.
it is possible third party applications may add these spns to computer accounts, filtering may be needed.
it is possible third party applications may have a computer account that adds computer accounts, filtering may be required.
legacy applications.
normal enterprise spn requests activity
service accounts used on legacy systems (e.g. netapp)
unlikely
web browsers and third party application might generate similar activity. an initial baseline is required.
windows domains with dfl 2003 and legacy systems