Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0157 — Detect Kerberoasting Attempts (T1558.003)
DET0157

Detect Kerberoasting Attempts (T1558.003)

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN0444 Analytic 0444
Windows

Detects Kerberoasting attempts by monitoring for anomalous Kerberos TGS requests (Event ID 4769) with RC4 encryption (etype 0x17), accounts requesting an unusual number of service tickets in a short period, or service accounts targeted outside normal usage baselines. Also correlates suspicious process activity (e.g., Mimikatz invoking LSASS access) with Kerberos ticket anomalies.

WinEventLog:Security EventCode=4769 WinEventLog:Sysmon EventCode=10 WinEventLog:Security EventCode=4624, 4648 WinEventLog:Security EventCode=4672
[TGSRequestThreshold] Number of TGS requests per account within a defined window; higher than baseline may indicate Kerberoasting.
[AllowedEncryptionTypes] Permitted Kerberos encryption algorithms; RC4 (etype 0x17) usage in modern environments is suspicious.
[ServiceAccountBaselines] Expected SPNs requested by specific accounts; anomalies may indicate adversarial targeting.
[TimeWindow] Correlation window for bursts of TGS requests; adjustable to reduce false positives.

Detected Techniques

1

Credential Access (1)

Details

MITRE ID
DET0157
STIX ID
x-mitre-detection-strategy--f1fe6286-1f54-4dfc-b96a-31b10711e4b1
Analytics
1
Techniques Detected
1
By Tactic
Credential Access
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.