Detect Forged Kerberos Tickets with Invalid Timestamps

This rule detects potential Kerberos Golden Ticket attacks by identifying Kerberos authentication service (AS) request events (EventID 4768) where the ticket encryption type is 0x17 (RC4-HMAC) and the difference between the event generation time and the ticket's start time is greater than one day. This large time difference can indicate a forged ticket with an invalid timestamp, a common characteristic of Golden Tickets. The rule then summarizes these events by target username and computer, flagging instances where three or more such events occur.