locked
ATA not detecting pth in my lab. RRS feed

  • Question

  • I've got 4 gateways capturing traffic for two domain controllers a piece. I've been playing around with mimikatz in the lab and I'm not seeing any pth alerts. I was able to dump credentials from about ten different servers without any alerts.

    Have I missed something? Do I need to forward traffic from the servers as well?

    Tuesday, July 14, 2015 3:03 PM

All replies

  • Looks like this was answered in another thread. The preview only detects pth when accessing resources on a DC.
    Tuesday, July 14, 2015 4:15 PM