UC-L3-027
Kerberoasting Detection
Windows Security Event Log
Use case development / Protect Identity Infrastructure / Detect Kerberoasting
sigma
Detection rule
title: Kerberoasting Service Ticket Request
status: experimental
description: Detects requests for service tickets with RC4 encryption
logsource:
product: windows
service: security
detection:
selection:
EventID: 4769
TicketEncryptionType: '0x17'
ServiceName|endswith: '$'
filter:
ServiceName: 'krbtgt'
condition: selection and not filter
falsepositives:
- Legacy applications requiring RC4
level: high
tags:
- attack.credential_access
- attack.t1558.003Test cases
- Request service ticket with Rubeus
False positive guidance
Identify and document legacy RC4 dependencies.