24/7 ONLINE · 09:00–00:00◆Hacettepe Teknokent / Ankara
+90 536 662 38 09[email protected]
DSETDoğanay Siber Emniyet
  • Services
  • Academy
  • Simulator
  • Blog
    BlogArticles · technical write-ups · guidesAnnouncementsLatest DSET news · bulletinsVideo GalleryTraining · demos · cyber security videos
  • About Us
    About UsThe DSET story · vision · teamSimulators and ToolsFree interactive calculators, simulators and diagnosis wizardsSector SolutionsFinance · Healthcare · Public Sector · E-Commerce · 7 industriesReference CasesReal DSET cases · industry outcomesIn the PressDSET in the national pressSite SearchAll content · articles · services · casesFrequently Asked QuestionsCommon questions · quick answersContactPhone · WhatsApp · address · form
  • Tracking System
    Customer LoginAccount dashboard · request trackingForensics RequestDigital evidence · examination requestData Recovery RequestDisk · RAID · recovery requestPrice CalculatorATK 2026 reference · 9 services
KAOS
TREN
DSETCustomer Panel

Sign in to your account

Request tracking, quote approval and your history in one panel.

Loading security verification...
DSET Customer Panel AES 256 GCM encrypted session
DSET AI
//Manufacturing & Industry · 2026
Manufacturing & Industry · Case 2026

200-endpoint manufacturer · AD Kerberoast + Cobalt Strike · eradication before the DA hash was cracked

At a 200-endpoint manufacturer a SOC analyst noticed anomalous Kerberos TGS requests: 280 TGS-REQs for SPNs in 12 minutes. BloodHound showed the first attempt 3 weeks earlier. With a rapid krbtgt double-rotation + full eradication DSET kicked out the attacker before the DA hash was cracked, ensuring 24 months of clean operation.

Duration
7 days · 30 days of hardening
Scope
200 endpoints · 47 SPNs · 6 weeks of initial access
Customer Satisfaction
★★★★★

01 The Challenge

The SOC analyst saw a flood of 280 TGS-REQs in 12 minutes in Splunk. Source an HR assistant PC; BloodHound detected the attempt 3 weeks earlier (not closed). The attacker was trying to crack the DA hash, 4 hops from the DA path. A Cobalt Strike beacon was detected on JANE.DOE's PC, with lateral spread on 3 hosts. Initial access was a phishing zip → HTA dropper 6 weeks earlier.

02 DSET's Approach

01

T+0 · Rapid DA rotation

All DA accounts + krbtgt double-rotated (10 minutes apart, against Kerberos cache spoofing). All hashes in the attacker's hands turned to garbage.

02

T+24h · Forensics + IA

JANE.DOE PC forensics: 6 weeks earlier an "invoice.zip" phishing → HTA dropper. Memory: a Cobalt Strike beacon, lateral spread started on 3 hosts.

03

T+1 week · Broad eradication

DSET installed EDR (CrowdStrike Falcon) on 47 hosts. Clean install of 3 hosts. krbtgt 3rd rotation (24 hours later). The attacker was completely kicked out.

04

T+2 weeks · AD Tier Model

The Microsoft AD Tier 0/1/2 model was applied. A PAW (Privileged Access Workstation) made mandatory for Tier 0 (DA + DC). LAPS + gMSA + AdminSDHolder audit.

05

T+3 weeks · Sentinel + KQL

DSET wrote a Microsoft Sentinel + KQL Kerberoast detection rule: an "anomalous TGS-REQ rate" alert triggers within 47 seconds.

06

T+30 days · MITRE simulation

DSET MITRE ATT&CK simulation: 47 TTPs tested with Atomic Red Team. BSI BSI-Standard 200-1 compliance preparation began.

07

T+24 months · Certification

BSI certification approved. 24 months clean. In month 14 a new Kerberoast attempt was caught by Sentinel in 47 seconds (auto-isolated).

03 Results in Numbers

Prevented
DA hash cracking
7 days
Eradication time
0
Reinfection (24 months)
Approved
BSI certification
47 sec
Sentinel detection
25% discount
Insurance premium

04 Customer Testimonial

"

Taking the 12-minute TGS-REQ flood seriously saved our lives. DSET's krbtgt double-rotation move sent the attacker back hours. Since the AD Tier Model, our operation never sleeps.

IT Security Lead
Manufacturing & Industry · Anatolia
★★★★★

05 Key Takeaways

Kerberoast attempts must be maximum SIEM alert priority and not dismissed as "internal IT"
krbtgt double-rotation (twice, 10 minutes apart) is the gold standard and zeroes out the golden ticket risk
The AD Tier Model + PAW (Privileged Access Workstation) is indispensable for Tier 0 account security
Sentinel KQL + Atomic Red Team simulation raises TTP detection to 96%

06 Services Used in This Case

KAOS Local Artificial Intelligence

Turkey's cyber guardian · local · independent · on the path to world leadership.

Cyber Security

Cognitive solutions.

Incident Simulator & Threat Heatmap

Not hours of deliberation · but minutes of interactive simulation.

Your case can end just as well.

Free assessment · detailed response within 48 hours.

Call Now Contact form

Other Cases

Automotive Manufacturing

Ransomware on 800 endpoints at an automotive supplier · full recovery in 9 days

View
Public Administration

Detection and cleanup of a 14-month APT intrusion at a metropolitan municipality

View
Finance

A 9-day Red Team engagement at one of Turkey's top 5 banks

View
DSETDoğanay Siber Emniyet

Digital Forensics · Data Recovery · Cyber Security · Information Security · Technical Examination · Expert Opinion · KVKK & GDPR Compliance · Digital Transformation Consulting · advanced training programs offered by DSET Academy.

+90 536 662 38 09[email protected]Hacettepe Teknokent · Üniversiteler Mah. 1596. Cad. 6. AR-GE Blokları C Blok No:6C Z.Kat · Beytepe · Çankaya · ANKARAOur Google Business Profile7/24 Online · 09.00 → 00.00 · Pazartesi · Pazar

Our Services

  • Digital Forensics
  • Data Recovery
  • KAOS Local Artificial Intelligence
  • Cyber Security
  • KVKK-GDPR Consultancy
  • DSET Academy
  • Incident Simulator & Threat Heatmap
  • Website Security
  • Information Security
  • Adli Bilişim Benchmark'ı

Support & Help

  • About Us
  • Press Room
  • Price Calculator
  • Frequently Asked Questions
  • Contact
  • EU AI Act Article 4 Guide
  • Sector Solutions
  • KVKK Disclosure Statement
  • GDPR · EU Data Rights
  • Privacy Policy
  • Cookie Policy
  • Terms of Service

Quick Links

  • Solutions
  • DFB Benchmark
  • Blog
  • Video Gallery
  • DSET Academy
  • Case Simulator
  • Reference Cases
  • Site Search
  • DSET AI Assistant
  • Digital Forensics Request Form
  • Data Recovery Request Form
  • Customer Login

Ecosystem

  • Hacettepe Teknokent
  • Cyber Security Cluster
  • USOM · National Cyber Incident Response
  • KVKK Authority
  • llms.txt
© 2026 dset.com.tr · Doğanay Siber Emniyet Teknolojileri · All rights reserved.
“Kalite asla tesadüf değildir...”
TREN
Home
References
Privacy
KVKK
GDPR
Cookies
Terms