Suspicious Kerberos RC4 Ticket Encryption

 Original Source: [Sigma source]
Title: Suspicious Kerberos RC4 Ticket Encryption
Status: test
Description:Detects service ticket requests using RC4 encryption type
References:
  -https://adsecurity.org/?p=3458
  -https://www.trimarcsecurity.com/single-post/TrimarcResearch/Detecting-Kerberoasting-Activity
Author: Florian Roth (Nextron Systems)
Date: 2017-02-06
modified:2022-06-19
Tags:
  • -'attack.credential-access'
  • -'attack.t1558.003'
Logsource:
  • product: windows
  • service: security
Detection:
  selection:
    EventID: '4769'
    TicketOptions: '0x40810000'
    TicketEncryptionType: '0x17'
  reduction:
    ServiceName|endswith: '$'
  condition:selection and not reduction
Falsepositives:
  -Service accounts used on legacy systems (e.g. NetApp)
  -Windows Domains with DFL 2003 and legacy systems
Level: medium