Campfire2
Question 1:
When did the ASREP Roasting attack occur, and when did the attacker request the Kerberos ticket for the vulnerable user?

Question 2:
Please confirm the User Account that was targeted by the attacker.
Question 3:
What was the SID of the account?
Question 4:
It is crucial to identify the compromised user account and the workstation responsible for this attack. Please list the internal IP address of the compromised asset to assist our threat-hunting team.
Question 5:
We do not have any artifacts from the source machine yet. Using the same DC Security logs, can you confirm the user account used to perform the ASREP Roasting attack so we can contain the compromised account/s?

Resources
Last updated