Most Important Detection 2026: Kerberoasting via Anomalous TGS-REQ Requests
This rule detects potential Kerberoasting activity by monitoring for high volumes of Kerberos TGS (Ticket Granting Service) requests using the weak RC4 encryption type (0x17) from a single account within a 5-minute window. It excludes machine accounts and common system service requests to reduce noise.
Splunk (SPL)

