Skip to content

Case-class playbook: identity-centric-v1 (Kerberoasting / AS-REP / Golden Ticket) #37

Description

@Juwon1405

Goal

Ship dart_playbook/identity-centric-v1.yaml for AD-centric attacks
where the entire kill chain pivots on identity primitives.

Why specialized

Classic AD attack chains (per Sean Metcalf, adsecurity.org):

AS-REP Roasting (T1558.004)

Kerberoasting (T1558.003)

LSASS dump via comsvcs.dll (T1003.001) ← BlackSuit / Akira

Pass-the-Hash / Pass-the-Ticket (T1550)

Golden Ticket (T1558.001) for persistence

Domain dominance + recovery denial

senior-analyst-v2.yaml covers these techniques but doesn't
specialize the phase-2 timeline order around AD events specifically.

Reference

  • Sean Metcalf — AD attack methodology
  • The DFIR Report — BlackSuit + Akira chain analyses
  • JPCERT/CC — Detecting Lateral Movement through Tracking Event Logs
  • CISA AA24-109A (Akira advisory, Nov 2025)

Acceptance

  • Specialized phase ordering: Kerberos events analyzed before MFT timeline
  • At least 4 identity-specific contradiction_triggers (incl. golden ticket pattern)
  • References cite Metcalf and JPCERT/CC

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:playbookArea: dart-playbook (YAML rules)phase-2Phase 2 — Agentic detection engineeringpost-sansDefer until after SANS submission (Jun 15)status:todoNot yet started

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions