Kerberoasting via RC4 Encrypted TGS Request

Detects Kerberos Ticket Granting Service (TGS) requests (Event ID 4769) that use RC4 encryption (0x17). In modern Active Directory environments, RC4 is considered weak and is often explicitly requested by attackers during Kerberoasting to facilitate offline brute-force cracking of service account passwords. The rule excludes common service accounts (e.g., krbtgt, machine accounts) to reduce noise.