Kerberos Forwardable+Proxiable+Renewable Combo with High-Risk Context
Detects Kerberos TGT or TGS requests that either exhibit a suspicious combination of ticket flags (Forwardable + Proxiable + Renewable) when associated with high-value targets, unusual accounts, or off-hours activity, or utilize the weak RC4-HMAC encryption type, both of which are indicative of ticket manipulation and credential theft.
Microsoft Sentinel (KQL)

