Most Important Detection 2026: AS-REP Roasting Against Pre-Auth-Disabled Account
This rule detects potential AS-REP Roasting attempts by identifying an unusually high volume of Kerberos AS-REQ requests (Event ID 4768) where the preauthentication type is set to 0. These requests are grouped by source IP or client address, and alerts are triggered when the number of unique accounts targeted or the total request count exceeds defined thresholds. AS-REP Roasting is an attack technique that attempts to retrieve a TGT for user accounts that have Kerberos preauthentication disabled, making them susceptible to offline brute-force password cracking.
CQL

