Title:Kerberoasting Activity - Initial Query Status:test Description:This rule will collect the data needed to start looking into possible kerberoasting activity.
Further analysis or computation within the query is needed focusing on requests from one specific host/IP towards multiple service names within a time period of 5 seconds.
You can then set a threshold for the number of requests and time between the requests to turn this into an alert.
References: -https://www.trustedsec.com/blog/art_of_kerberoast/ -https://adsecurity.org/?p=3513 Author: @kostastsale Date: 2022-01-21 modified:2025-10-19 Tags:
filter_main_machine_accounts: TargetUserName|contains:
'$@' condition:selection and not 1 of filter_main_* Falsepositives:
-Legacy applications. Level:medium