DC Machine Account TGT Request from Non-DC Source IP
Description
Detects a Kerberos TGT request (Event 4768) for a known Domain Controller machine account originating from an IP address that is not a known Domain Controller. DC machine accounts should only request TGTs from their own IP. Any TGT request for a DC account from a workstation or non-DC host is anomalous and indicates one of the following:
- PKINIT abuse (CVE-2026-54121 / Certighost): attacker authenticating as a DC via a forged certificate from their workstation
- Overpass-the-Hash: attacker converting a stolen DC machine account NTLM hash into a Kerberos TGT
- Pass-the-Hash (RC4): attacker using the DC machine account hash directly with Kerberos
Query · sigma
selection: EventID: 4768 Status: '0x0' TargetUserName|endswith: $ TargetUserName|expand: '%dc_machine_accounts%' filter_main_dc_source: IpAddress|expand: '%dc_ip_addresses%' filter_main_loopback: - IpAddress: - 127.0.0.1 - ::1 - ::ffff:127.0.0.1 - '-' - IpAddress|startswith: 'fe80:' condition: selection and not 1 of filter_main_*
Known false positives
- Unlikely if %dc_machine_accounts% and %dc_ip_addresses% are correctly populated.