Weak Encryption Enabled and Kerberoast

 Original Source: [Sigma source]
Title: Weak Encryption Enabled and Kerberoast
Status: test
Description:Detects scenario where weak encryption is enabled for a user profile which could be used for hash/password cracking.
References:
  -https://adsecurity.org/?p=2053
  -https://blog.harmj0y.net/redteaming/another-word-on-delegation/
Author: @neu5ron
Date: 2017-07-30
modified:2021-11-27
Tags:
  • -'attack.defense-impairment'
  • -'attack.t1685'
Logsource:
  • product: windows
  • service: security
  • definition: Requirements: Audit Policy : Account Management > Audit User Account Management, Group Policy : Computer Configuration\Windows Settings\Security Settings\Advanced Audit Policy Configuration\Audit Policies\Account Management\Audit User Account Management
Detection:
  selection:
    EventID: '4738'
  olduac_des:
    OldUacValue|endswith:
      -'8???'
      -'9???'
      -'A???'
      -'B???'
      -'C???'
      -'D???'
      -'E???'
      -'F???'

  newuac_des:
    NewUacValue|endswith:
      -'8???'
      -'9???'
      -'A???'
      -'B???'
      -'C???'
      -'D???'
      -'E???'
      -'F???'

  olduac_preauth:
    OldUacValue|endswith:
      -'1????'
      -'3????'
      -'5????'
      -'7????'
      -'9????'
      -'B????'
      -'D????'
      -'F????'

  newuac_preauth:
    NewUacValue|endswith:
      -'1????'
      -'3????'
      -'5????'
      -'7????'
      -'9????'
      -'B????'
      -'D????'
      -'F????'

  olduac_encrypted:
    OldUacValue|endswith:
      -'8??'
      -'9??'
      -'A??'
      -'B??'
      -'C??'
      -'D??'
      -'E??'
      -'F??'

  newuac_encrypted:
    NewUacValue|endswith:
      -'8??'
      -'9??'
      -'A??'
      -'B??'
      -'C??'
      -'D??'
      -'E??'
      -'F??'

  condition:selection and ((newuac_des and not olduac_des) or (newuac_preauth and not olduac_preauth) or (newuac_encrypted and not olduac_encrypted))
Falsepositives:
  -Unknown
Level: high