definition: The advanced audit policy setting "Account Logon > Kerberos Authentication Service" must be configured for Success/Failure
Detection: selection: EventID:
'4768' TargetUserName|endswith:
'$' CertThumbprint|contains:
'*' filter_local: IpAddress:
'::1' filter_thumbprint: CertThumbprint:
'' condition:selection and not 1 of filter_* Falsepositives:
-False positives are possible if the environment is using certificates for authentication. We recommend filtering Account_Name to the Domain Controller computer accounts. Level:high