Unconstrained Delegation Abuse: TGT Extraction via LSASS Access

This rule detects potential extraction or caching of Kerberos Ticket-Granting Tickets (TGT) by correlating Kerberos authentication events (4768/4769) with unauthorized access to the Local Security Authority Subsystem Service (lsass.exe). This pattern is often indicative of credential dumping tools like Mimikatz targeting Kerberos tickets on systems potentially used for delegation attacks.