Suspected suspicious Kerberos ticket request on one endpoint

Copper Contributor

Hi

 

The documentation for the alert “Suspected suspicious Kerberos ticket request on one endpoint”  with 

UniqueExternalId  2418 seems to be missing.

The alert references https://aka.ms/suspiciouskerberosticketrequest, which  leads to the Bing search engine page.

 

Nothing here either:
https://docs.microsoft.com/en-us/defender-for-identity/suspicious-activity-guide

 

Is there any further documentation available or planned?

 

Thanks

5 Replies

@Eli Ofekany comments perhaps? I see the aka.ms shortcut has been fixed but now just points to the second link noted above, which still does not contain any further detail.

We will add the information about this alert in our public docs soon.
Hi Daniel - any news on this?
Documentation should be live by the end of the month
Bumping this one..... seems it has not arrived yet.