Title:
Suspicious Kerberos RC4 Ticket Encryption
Status:
test
Description:Detects service ticket requests using RC4 encryption type
References:
-https://adsecurity.org/?p=3458
-https://www.trimarcsecurity.com/single-post/TrimarcResearch/Detecting-Kerberoasting-Activity
Author: Florian Roth (Nextron Systems)
Date: 2017-02-06
modified:2022-06-19
Tags:
- -'attack.credential-access'
- -'attack.t1558.003'
Logsource:
- product: windows
- service: security
Detection:
selection:
EventID:
'4769'
TicketOptions:
'0x40810000'
TicketEncryptionType:
'0x17'
reduction:
ServiceName|endswith:
'$'
condition:
selection and not reduction
Falsepositives:
-Service accounts used on legacy systems (e.g. NetApp)
-Windows Domains with DFL 2003 and legacy systems
Level:
medium