Suspicious Kerberos Service Ticket Patterns
Detects two suspicious Kerberos activity patterns indicative of potential credential theft or reconnaissance: 1) A single account requesting tickets for multiple services or across multiple hosts in a short duration, which may indicate automated credential harvesting such as Kerberoasting; 2) The use of RC4 encryption (0x17) for Kerberos tickets, which is an older, weaker protocol and may indicate a forced downgrade attack to facilitate offline password cracking.
Microsoft Sentinel (KQL)

