Kerberoasting via RC4-HMAC Kerberos Ticket Request (T1558.003)
This rule monitors Kerberos Ticket Granting Service (TGS) requests (Event ID 4769) for weak RC4-HMAC (0x17) encryption, which is a strong indicator of a Kerberoasting attack. It aggregates these requests to identify potentially malicious activity by grouping by account and destination service, while excluding legitimate machine accounts, built-in service identities, and internal Kerberos service requests.
Microsoft Sentinel (KQL)

