Capture the Kerberos Flag: Detecting Kerberos Anomalies (opens in new tab)
Improve Kerberos detection with TGT TicketOptions analysis. Use KQL binary shifts and bitwise ops on Event 4768 to find suspicious flag combinations fast.
Read the original article