Kerberoasting Attack Attempt on Domain Controller
This rule detects potential Kerberoasting activity by monitoring for high volumes of Kerberos TGS (Ticket Granting Service) requests (Event ID 4769) using the RC4 encryption type (0x17) within a short timeframe. Kerberoasting involves requesting tickets for service accounts to offline crack their passwords. The rule filters out known service accounts and system-level accounts ending in '$'.
Microsoft Sentinel (KQL)

