Windows: Uncommon Outbound Kerberos Traffic on Port 88

Alerts on initiated outbound connections to Kerberos TCP/88 from unexpected Windows processes.

FreeReviewedSigma · Medium · v2
Product
windows
Category
network_connection
Author
Ilyas Ochkov, oscd.community (SigmaHQ), DRL 1.1
Published
2019-10-24
Updated
2026-07-31

ATT&CK techniques

Defense Evasion → Lateral Movement
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule flags outbound network connections to the Kerberos default port (88) that were initiated by the host. Such traffic can indicate attacker activity related to lateral movement or delegation-based privilege escalation. The detection relies on Windows network connection telemetry that includes destination port, initiation status, and the initiating process image, while filtering out common processes to reduce expected benign activity.

Related detections9 linkedT1558 — drag to rearrange
Malicious Kerberos proxiable/S4U2self Ticket - CVE-2021-42278/42287 (via security)
Malicious Rubeus Kerberos Unconstrained Delegation Abuse (via security)
Malicious Rubeus Kerberos Constrained Delegation Abuse - S4U2Proxy (via security)
Renamed Mimikatz Credential Theft Command Indicators (via process_creation)
Windows PowerShell ScriptBlock: Get-ADComputer reconnaissance for unconstrained delegation properties
Rubeus HackTool Execution via PowerShell ScriptBlock Flags (Windows)
Windows Kerberos Replay Attack Likely Activity on Domain Controllers (Event ID 4649)
Windows: Detect KrbRelayUp.exe HackTool Process Execution
Windows HackTool Activity: Mimikatz Kerberos Ticket and MemSSP File Creation
Windows: Uncommon Outbound Kerberos Traffic on Port 88
Pivot detection · T1558 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.