Kerberoasting: Bursty RC4 TGS Requests Followed by Dormant Account Logon
This rule detects potential Kerberoasting activity by identifying an abnormal volume of RC4-encrypted Ticket Granting Service (TGS) requests (Event 4769) targeting service accounts, followed closely by a successful logon (Event 4624) from a previously dormant service account, suggesting the successful use of a cracked service ticket for unauthorized authentication.
Microsoft Sentinel (KQL)

