Kerberoasting via PowerShell - T1558.003
This rule detects the execution of PowerShell commands and scripts known to be used for Kerberoasting, a technique for obtaining TGS tickets that can be cracked offline to recover service account passwords. The rule matches specific tool names and command line flags associated with common offensive security tools.
SentinelOne

