Golden Ticket Kerberos TGT Anomalies (T1558.001)

Detects anomalous Kerberos ticket requests that are characteristic of Golden Ticket attacks. The rule flags the use of weak encryption types (e.g., RC4) commonly used in forged tickets even in AES-enforced environments, and direct requests for the KRBTGT service account outside of legitimate ticket renewal operations.