A user requested multiple service tickets
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
10 Minutes
Deduplication Period
1 Day
Required Data
Requires one of the following data sources: Windows Event Collector OR XDR Agent with eXtended Threat Hunting (XTH)
Detection Modules
Identity Analytics
ATT&CK Tactic
Credential Access (TA0006)
ATT&CK Technique
Steal or Forge Kerberos Tickets: Kerberoasting (T1558.003)
Severity
Informational
Description
A user requested multiple service tickets. This is typically a sign of a Kerberoasting attack.
Attacker's Goals
Crack account credentials by obtaining an easy-to-crack Kerberos ticket.
Investigative actions
Check who used the host at the time of the alert, to rule out a benign service or tool requesting weak Kerberos encryption.
Variations
PreviousA user rejected an SSO request from an unusual country
NextA user sent multiple TGT requests to irregular service
Was this helpful?
