Detection catalogue
Explore published rules with transparent provenance, licensing, and ATT&CK mappings.
- detections
Loading detections…
Explore published rules with transparent provenance, licensing, and ATT&CK mappings.
Loading detections…
Identifies directory-service access or creation events involving a MicrosoftDNS record that contains a base64-encoded blob matching the pattern "UWhRCA...BAAAA". This blob pattern corresponds to a marshaled CREDENTIAL_TARGET_INFORMATION structure associated with DNS-based SPN spoofing used in Kerberos coercion tradecraft. Adversaries may abuse such records to coerce victim systems into authenticating to attacker-controlled hosts while requesting Kerberos tickets for legitimate services.
Published to signed-in readers
The query as its source wrote it, its canonical form, and the content hash that pins this exact revision.