Kerberoasting RC4 Downgrade via Multiple 4769 Requests - T1558.003
Detects an abnormally high volume of Kerberos TGS (Ticket Granting Service) requests encrypted with RC4 (0x17) from a single source IP. This behavior is indicative of Kerberoasting, an attack where an adversary attempts to extract service account passwords from requested TGS tickets.
Splunk (SPL)

