Skip to main content
Skip to main content
Published Nov 22, 2020 | Updated Nov 22, 2023

VirTool:Win32/Kekeo

Detected by Microsoft Defender Antivirus

Aliases: No associated aliases

Summary

Kekeo (also known as Rubeus) is a command-line tool crafted to exploit and manipulate Kerberos authentication in Windows Active Directory.

It's mainly employed for launching Kerberos-based attacks like ticket grabbing, ticket manipulation, and pass-the-ticket exploits.

VirTool:Win32/Kekeo is a 32-bit Windows variant that offers an interface for misusing Kerberos functionality to elevate privileges, impersonate users, and obtain unauthorized access to resources in a compromised Active Directory setting.

To mitigate the risk of Kekeo infection and protect against the attacks it facilitates on the Kerberos authentication protocol, the following actions can be taken:

  • Start by updating your systems regularly with Microsoft's patches. 
  • Ensure robust password policies—complex and changed regularly to thwart attackers.
  • Manage service accounts diligently, avoid overly privileged ones, and follow the principle of least privilege. Implement Microsoft's Credential Guard to safeguard Kerberos credentials.
  • Use network monitoring and intrusion detection systems to detect threats. Tailor password policies for high-risk accounts with fine-grained control.
  • Minimize privileged accounts and limit access to sensitive ones while conducting regular reviews. Enable Kerberos event auditing and centralized logging for vigilant defense.
  • Finally, empower your community with security awareness, recognizing and reporting threats, and fostering strong password practices. This journey strengthens your digital fortress against Kekeo attacks.

 

Microsoft Defender Antivirus automatically removes threats as they are detected. However, many infections can leave remnant files and system changes. Updating your antimalware definitions and running a full scan might help address these remnant artifacts.

You can also visit our advanced troubleshooting page or search the Microsoft virus and malware community for more help.

 

Follow us