Kerberoasting Activity Detection

This rule detects potential Kerberoasting activity by identifying an unusual number of Kerberos service ticket requests (Event ID 4769) for service principal names (SPNs) ending with '$' from a single client address within an hour. A high count (over 10) is flagged as 'High' suspicion, while a count between 5 and 10 is flagged as 'Medium'. This behavior is indicative of an attacker attempting to obtain service ticket hashes for offline cracking.