Free kit

Free AI Tabletop Exercise Kit for SMBs

Sign up for the Cyber Defense & AI Brief and get it free.

Get the free kit

UC-L3-027

Kerberoasting Detection

Windows Security Event Log

Use case development / Protect Identity Infrastructure / Detect Kerberoasting

sigma

Detection rule

title: Kerberoasting Service Ticket Request
status: experimental
description: Detects requests for service tickets with RC4 encryption
logsource:
  product: windows
  service: security
detection:
  selection:
    EventID: 4769
    TicketEncryptionType: '0x17'
    ServiceName|endswith: '$'
  filter:
    ServiceName: 'krbtgt'
  condition: selection and not filter
falsepositives:
  - Legacy applications requiring RC4
level: high
tags:
  - attack.credential_access
  - attack.t1558.003

Test cases

  • Request service ticket with Rubeus

False positive guidance

Identify and document legacy RC4 dependencies.

ATT&CK

Detection course