title: Kerberoasting Activity - Initial Query id: d04ae2b8-ad54-4de0-bd87-4bc1da66aa59 status: test description: | This rule will collect the data needed to start looking into possible kerberoasting activity. Further analysis or computation within the query is needed focusing on requests from one specific host/IP towards multiple service names within a time period of 5 seconds. You can then set a threshold for the number of requests and time between the requests to turn this into an alert. references: - https://www.trustedsec.com/blog/art_of_kerberoast/ - https://adsecurity.org/?p=3513 author: '@kostastsale' date: 2022-01-21 modified: 2025-10-19 tags: - attack.credential-access - attack.t1558.003 logsource: product: windows service: security detection: selection: EventID: 4769 Status: '0x0' # Translated as status from failure code field. Query only for successes TicketEncryptionType: '0x17' # RC4 ticket encryption type filter_main_krbtgt: ServiceName|endswith: - 'krbtgt' # Ignore requests for the krbtgt service - '$' # Ignore requests from service names that end with $ which are associated with genuine kerberos traffic filter_main_machine_accounts: TargetUserName|contains: '$@' # Ignore requests from machines condition: selection and not 1 of filter_main_* falsepositives: - Legacy applications. level: medium