Quiz 2 Question 2 of 20

A SOC analyst reviews SIEM logs and notices a sudden spike in Kerberos TGS-REQ packets originating from a single workstation, targeting multiple Service Principal Names (SPNs) across the domain. The tickets are encrypted with RC4-HMAC. The workstation’s EDR shows no process injection or lateral movement. What is the most likely indicator of malicious activity in this scenario?

Select an answer to reveal the explanation.

Motivation