AS-REP Roasting Potential Enumeration

Detects Kerberos AS-REQ events (Event ID 4768) where accounts with Kerberos pre-authentication disabled successfully request an AS-REP ticket. Attackers exploit these accounts by requesting encrypted AS-REP blobs to perform offline password cracking. The rule flags potential enumeration when multiple unique accounts are targeted from the same source within a short timeframe.