A user sent multiple TGT requests to irregular service
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
10 Minutes
Deduplication Period
1 Day
Required Data
Requires one of the following data sources: Windows Event Collector OR XDR Agent with eXtended Threat Hunting (XTH)
Detection Modules
Identity Analytics
ATT&CK Tactic
Credential Access (TA0006)
ATT&CK Technique
Steal or Forge Kerberos Tickets: Kerberoasting (T1558.003)
Severity
Low
Description
A user sent multiple TGT requests to services other than KRBTGT and KADMIN. This is typically a sign of a Kerberoasting attack.
Attacker's Goals
Crack account credentials by obtaining an easy-to-crack Kerberos ticket.
Investigative actions
Check who used the host at the time of the alert, to rule out a benign service or tool requesting weak Kerberos encryption.
Variations
Was this helpful?
