Kerberoasting: Bursty RC4 TGS Requests for Non-krbtgt SPNs (4769)

Detects anomalous Kerberos TGS (Ticket Granting Service) requests using weak RC4-HMAC (0x17) encryption. The rule looks for accounts requesting multiple service tickets for distinct Service Principal Names (SPNs) within a short time window, which is a common behavior pattern for tools like Rubeus or GetUserSPNs.py during the credential-harvesting phase of a Kerberoasting attack.