Kerberos ticket abuse: Rubeus tooling and RC4 ticket downgrades
Detects the execution of Rubeus, a common security tool used for Kerberos-based attacks including Golden/Silver Ticket forgery, AS-REP roasting, Kerberoasting, and ticket harvesting. The rule monitors command-line indicators associated with known Rubeus arguments.
Microsoft Sentinel (KQL)

