Kerberoasting via RC4 TGS-REQ Bursts (T1558.003)
This rule monitors for an abnormally high number of Kerberos Ticket Granting Service (TGS) requests using the RC4-HMAC encryption type (0x17) from a single IP address to various service accounts. This pattern is indicative of Kerberoasting, a technique where attackers attempt to obtain service tickets to crack service account passwords offline.
CQL

