TGViewer
Soc Root Soc Root @socroot · 686 subscribers
Post #313 197
🔐 NTLM یا Kerberos?

وقتی با Windows و Active Directory کار می‌کنیم، دو پروتکل مهم Authentication داریم:

🔹 NTLM
🔹 Kerberos

اینجا NTLM از روش Challenge-Response استفاده می‌کنه:

Client → Challenge → Response → Authentication

یکی از Eventهای مهمش:

4776 → Credential Validation


ولی Kerberos روش Ticket-Based Authentication رو استفاده می‌کنه.

کاربر ابتدا از KDC یک Ticket می‌گیره و بعد برای دسترسی به سرویس‌ها از Ticket استفاده می‌کنه.

یکسری Event های مهم:

4768 → TGT Request
4769 → Service Ticket Request
4771 → Kerberos Authentication Failed

⚔️ تفاوت خیلی خلاصه:

NTLM → Challenge / Response
Kerberos → Ticket



👨‍💻 برای SOC Analyst مهمه بدونیم Authentication با چه پروتکلی انجام شده؛ چون Eventهای NTLM و Kerberos مسیرهای متفاوتی برای Investigation بهمون میدن.


@Socroot
  • 👌 3
More from @socroot
  1. Oct 4, 2026بریم ادامه کار 🫡 🔹 Audit Kerberos Authentication Service این یکی مربوط به Kerberos Authe…
  2. Oct 3, 2026⚠️ یه نکته هم اضافه کنم : در کل این کتگوری Account Logon رو ، روی AD فعال میکنن . (روی End…
  3. Oct 3, 2026🔐 Windows Advanced Audit Policy | Account Logon - Audit Credential Validation اگه با Wind…
  4. Oct 3, 2026از اونجایی که من ارادت خاصی به Windows log Analysis دارم به شدت درگیر کار و مطالعه Group P…
  5. Oct 2, 2026Soc Root pinned «🔴 موارد کاربردی که تا الان در کانال Soc Root منتشر شده : 🔹️مجموعه ۴۰۰ ن…
  6. Oct 2, 2026🔴 موارد کاربردی که تا الان در کانال Soc Root منتشر شده : 🔹️مجموعه ۴۰۰ نکته کاربردی +Netw…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →