Standardlikelihood: Mediumseverity: HighDraft
CAPEC-652Use of Known Kerberos Credentials
Abstraction
Standard
Status
Draft
Likelihood
Medium
Severity
High
Description
An adversary obtains (i.e. steals or purchases) legitimate Kerberos credentials (e.g. Kerberos service account userID/password or Kerberos Tickets) with the goal of achieving authenticated access to additional systems, applications, or services within the domain.
Metadata: standard CAPEC pattern, status draft, likelihood medium, severity high. Underlying weaknesses: CWE-522, CWE-307, CWE-308, CWE-309, CWE-262 (and 4 more). Mapped ATT&CK technique: [object Object]. Related CAPEC patterns: [object Object], [object Object].
Related weaknesses· 9
MITRE ATT&CK crosswalk· 1
Related attack patterns· 2
Exploits9
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Use of Single-factor Authenticationcwe-308 | 100% | live |
| Weakness | Authentication Bypass by Capture-replaycwe-294 | 100% | live |
| Weakness | Password Aging with Long Expirationcwe-263 | 100% | live |
| Weakness | Use of Password System for Primary Authenticationcwe-309 | 100% | live |
| Weakness | Use of Password Hash Instead of Password for Authenticationcwe-836 | 100% | live |
| Weakness | Insufficiently Protected Credentialscwe-522 | 100% | live |
| Weakness | Reliance on a Single Factor in a Security Decisioncwe-654 | 100% | live |
| Weakness | Improper Restriction of Excessive Authentication Attemptscwe-307 | 100% | live |
| Weakness | Not Using Password Agingcwe-262 | 100% | live |
Related to1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Technique | Steal or Forge Kerberos Ticketst1558 | 100% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.