
Findings and evidence
Kaspersky explains a network-anomaly approach using Kerberos and DNS traffic as examples. The method compares protocol behavior with a host’s usual activity to identify suspicious patterns that may resemble legitimate enterprise traffic.
Why it matters
Detection validation should include a documented baseline, known administrative activity and a review of false positives. Retain the underlying events so another analyst can test the explanation for an anomaly.
Scope and limits
This is a vendor-specific technical explanation, not an independent comparative benchmark. An unusual pattern is a lead to investigate rather than a verdict.
Primary source
Kaspersky / Securelist: original publication. Source published 2026-07-31. Brief prepared by websec.gr on 26 September 2026. This is an editorial research summary, not a claim of independent replication.