Hello, how are you guys ?
After I made the configuration above, a lot of Possibly golden ticket messages are appearing, between 3 servers, both have lateral communication through the Veeam backup tool, but in the alert I can't find this information.I needed to disable the active response, as it was blocking the host all the time:<active-response><disabled>yes</disabled><command>netsh</command>
<location>local</location>
<level>7</level>
<rules_id>100100</rules_id>
<timeout>60</timeout>
</active-response>
wazuh-alerts-4.x-2023.10.1800710.0.0.6*****NTLM%%1842%%183310.0.0.1658203128NTLM V2{00000000-0000-0000-0000-000000000000}NtLmSsp30x00x0S-1-0-0****0x00x22d9acc1ger.*****S-1-5-21-928559543-438945549-723327098-1001%%1843****Security****462470211230x802000000000000000680{54849625-5478-4994-a5ba-3e3b0328c30d}Microsoft-Windows-Security-AuditingAUDIT_SUCCESS2023-10-18T14:00:03.3569641Z1254496482windows_eventchannel1697637605.15838127logEventChannelSiemServer.startlink.localPossible Golden Ticket attack2security_event, windows11000312trueOct 18, 2023 @ 11:00:05.127