SPN Enumeration via setspn.exe or LDAP servicePrincipalName Query
This rule detects potential Kerberoasting reconnaissance activities by monitoring for the usage of 'setspn.exe' (Event ID 4688) or LDAP queries involving 'servicePrincipalName' (Event ID 1644). Adversaries use these methods to identify service accounts in the domain to target for ticket requests.
Microsoft Sentinel (KQL)

