Suspicious Kerberos Ticket Request via CLI

 Original Source: [Sigma source]
Title: Suspicious Kerberos Ticket Request via CLI
Status: experimental
Description:Detects suspicious Kerberos ticket requests via command line using System.IdentityModel.Tokens.KerberosRequestorSecurityToken class. Threat actors may use command line interfaces to request Kerberos tickets for service accounts in order to perform offline password cracking attacks commonly known as Kerberoasting or other Kerberos ticket abuse techniques like silver ticket attacks. Encoded commands will not surface the class name, so the ps_script rule covers that instead.
References:
  -https://www.huntress.com/blog/gootloader-threat-detection-woff2-obfuscation
  -https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1558.003/T1558.003.md#atomic-test-4---request-a-single-ticket-via-powershell
  -https://learn.microsoft.com/en-us/dotnet/api/system.identitymodel.tokens.kerberosrequestorsecuritytoken?view=netframework-4.8.1
Author: Swachchhanda Shrawan Poudel (Nextron Systems)
Date: 2025-11-18
modified:2026-09-14
Tags:
  • -'attack.credential-access'
  • -'attack.t1558.003'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
    - Image|endswith:
      - '\powershell.exe'
      - '\pwsh.exe'
    - OriginalFileName:
      - 'powershell.exe'
      - 'pwsh.dll'
  selection_cli:
    CommandLine|contains: 'System.IdentityModel.Tokens.KerberosRequestorSecurityToken'
  condition:all of selection_*
Falsepositives:
  -Legitimate command line usage by administrators or security tools
Level: high