Kerberoasting Activity - Initial Query

 Original Source: [Sigma source]
Title: Kerberoasting Activity - Initial Query
Status: test
Description:This rule will collect the data needed to start looking into possible kerberoasting activity. Further analysis or computation within the query is needed focusing on requests from one specific host/IP towards multiple service names within a time period of 5 seconds. You can then set a threshold for the number of requests and time between the requests to turn this into an alert.
References:
  -https://www.trustedsec.com/blog/art_of_kerberoast/
  -https://adsecurity.org/?p=3513
Author: @kostastsale
Date: 2022-01-21
modified:2025-10-19
Tags:
  • -'attack.credential-access'
  • -'attack.t1558.003'
Logsource:
  • product: windows
  • service: security
Detection:
  selection:
    EventID: '4769'
    Status: '0x0'
    TicketEncryptionType: '0x17'
  filter_main_krbtgt:
    ServiceName|endswith:
      -'krbtgt'
      -'$'

  filter_main_machine_accounts:
    TargetUserName|contains: '$@'
  condition:selection and not 1 of filter_main_*
Falsepositives:
  -Legacy applications.
Level: medium