During a threat hunt, an analyst finds that an attacker used Kerberoasting. Which indicator would appear in Defender for Identity alerts?
-
A
Abnormal Kerberos ticket request for a service account with a weak encryption type
-
B
Pass-the-Ticket activity using a stolen TGT
-
C
NTLM relay attack against a domain controller
-
D
Suspected overpass-the-hash attack