detecting-golden-ticket-attacks-in-kerberos-logs
Pass
Audited by Gen Agent Trust Hub on Jun 16, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill contains purely informational content and configuration-based detection queries (Splunk and KQL) for cybersecurity threat hunting. There are no executable scripts, remote downloads, or credential-accessing commands present. The skill provides guidance on monitoring standard Windows Event IDs (4768, 4769, 4771) to detect Kerberos anomalies.
Audit Metadata