AS-REP Roasting: Multiple No-PreAuth AS-REQ from Single Source

This rule detects potential AS-REP Roasting activity by monitoring Windows Event ID 4768 (TGT Request). It identifies multiple Kerberos AS-REQ requests from a single IP address within a 10-minute window, where the PreAuthType is 0 (indicating no pre-authentication) and the encryption type is RC4 (0x17 or 23). This behavior is characteristic of enumeration and exploitation tools such as Rubeus or Impacket's GetNPUsers.py, which attempt to obtain extractable TGTs for accounts that do not require Kerberos pre-authentication.