Unconstrained Delegation Abuse: TGT Extraction via LSASS Access
This rule detects potential extraction or caching of Kerberos Ticket-Granting Tickets (TGT) by correlating Kerberos authentication events (4768/4769) with unauthorized access to the Local Security Authority Subsystem Service (lsass.exe). This pattern is often indicative of credential dumping tools like Mimikatz targeting Kerberos tickets on systems potentially used for delegation attacks.
Microsoft Sentinel (KQL)

