Most Important Detection 2026: Kerberoasting via Abnormal RC4 TGS Requests

This rule detects potential Kerberoasting activity by monitoring Kerberos TGS requests (Event ID 4769) that use RC4 encryption (0x17 or 17). It identifies accounts requesting TGS tickets for a large number of unique Service Principal Names (SPNs), excluding requests for host-based services (ending in $). High volumes of such requests from a single user are indicative of an attempt to gather service tickets for offline password cracking.