Forced Authentication T1187
Tactic: Credential Access
Adversaries may gather credential material by invoking or forcing a user to automatically provide authentication information through a mechanism in which they can intercept.
Events covered
16 catalog events are tagged with this technique by at least one rule.
| Provider | Event | Title |
|---|---|---|
| Sysmon | Event ID 1 | Process creation |
| Sysmon | Event ID 3 | Network connection |
| Sysmon | Event ID 11 | FileCreate |
| Sysmon | Event ID 22 | DNSEvent (DNS query) |
| Security-Auditing | Event ID 4624 | An account was successfully logged on. |
| Security-Auditing | Event ID 4625 | An account failed to log on. |
| Security-Auditing | Event ID 4662 | An operation was performed on an object. |
| Security-Auditing | Event ID 4688 | A new process has been created. |
| Security-Auditing | Event ID 4768 | A Kerberos authentication ticket (TGT) was requested. |
| Security-Auditing | Event ID 5136 | A directory service object was modified. |
| Security-Auditing | Event ID 5137 | A directory service object was created. |
| Security-Auditing | Event ID 5145 | A network share object was checked to see whether client can be granted desired access. |
| Defender-DeviceLogonEvents | LogonSuccess | Logon succeeded |
| Defender-DeviceNetworkEvents | any | Network activity |
| Defender-DeviceNetworkEvents | ConnectionSuccess | Connection succeeded |
| Defender-DeviceNetworkEvents | ConnectionAttempt | Connection attempt |
Authoring guide
These 30 rules share fields, values, and exclusions.
Fields filtered most (54 distinct)
These fields appear most often in rule filters.
Top indicator values (137 distinct)
These values appear most often in rule predicates.
Exclusions (39 distinct)
These values appear most often in top-level exclusions.
Rules under this technique
These vendors publish rules tagged with this technique.
Sigma 9 rules
- Attempts of Kerberos Coercion Via DNS SPN Spoofing
- NTLM Hash Leak Via Curl NTLM Authentication
- PetitPotam Suspicious Kerberos TGT Request
- Possible PetitPotam Coerce Authentication Attempt
- Potential CVE-2026-33829 Exploitation - Windows Snipping Tool Remote File Path URI
- Potential PetitPotam Attack Via EFS RPC Calls
- Suspicious Creation of .library-ms File — Potential CVE-2025-24054 Exploit
- Suspicious DNS Query Indicating Kerberos Coercion via DNS Object SPN Spoofing
- Suspicious DNS Query Indicating Kerberos Coercion via DNS Object SPN Spoofing - Network
Elastic 11 rules
- Active Directory Forced Authentication from Linux Host - SMB Named Pipes
- Potential Computer Account NTLM Relay Activity
- Potential Kerberos Coercion via DNS-Based SPN Spoofing
- Potential Kerberos Relay Attack against a Computer Account
- Potential Kerberos SPN Spoofing via Suspicious DNS Query
- Potential Local NTLM Relay via HTTP
- Potential Machine Account Relay Attack via SMB
- Potential Net-NTLM Coercion via Snipping Tool ms-screensketch URI (CVE-2026-33829)
- Potential NTLM Relay Attack against a Computer Account
- Rare Connection to WebDAV Target
- Rare SMB Connection to the Internet
Splunk 6 rules
- DNS Kerberos Coercion
- PetitPotam Network Share Access Request
- Windows Credential Target Information Structure in Commandline
- Windows Kerberos Coercion via DNS
- Windows Short Lived DNS Record
- Windows Theme File Creation in Unusual Location