AS-REP Roasting Enumeration on Domain Controller

This rule detects potential AS-REP Roasting activity by monitoring for a single source IP address requesting Kerberos TGTs (Event ID 4768) for multiple distinct user accounts within a 10-minute window. This behavior often indicates an attacker attempting to identify and harvest Kerberos pre-authentication hashes from accounts that do not require pre-authentication, which can then be cracked offline.