Rubeus Execution for Kerberos Ticket Abuse and Kerberoasting
Detects the execution of the Rubeus.exe utility with command-line arguments indicative of Kerberos-related credential harvesting and abuse, such as Kerberoasting, AS-REP Roasting, and Pass-the-Ticket attacks.
Microsoft Sentinel (KQL)

