Kerberoasting RC4 Encryption Downgrade via Kerberos TGS Requests
This rule detects potential Kerberoasting activity by monitoring Windows Event ID 4769 (Kerberos service ticket request). It identifies excessive requests for service tickets using RC4 encryption (0x17) by a single account within a 10-minute window, excluding common service accounts and krbtgt requests.
Microsoft Sentinel (KQL)

