Cross-source coverage

T1558.003 / ATT&CK

Steal or Forge Kerberos Tickets: Kerberoasting

38 rules · 37 families across 5 sources.

From MITRE ATT&CK 19.2

Adversaries may abuse a valid Kerberos ticket-granting ticket (TGT) or sniff network traffic to obtain a ticket-granting service (TGS) ticket that may be vulnerable to Brute Force.

Service principal names (SPNs) are used to uniquely identify each instance of a Windows service. To enable authentication, Kerberos requires that SPNs be associated with at least one service logon account (an account specifically tasked with running a service).

Adversaries possessing a valid Kerberos ticket-granting ticket (TGT) may request one or more Kerberos ticket-granting service (TGS) service tickets for any SPN from a domain controller (DC). Portions of these tickets may be encrypted with the RC4 algorithm, meaning the Kerberos 5 TGS-REP etype 23 hash of the service account associated with the SPN is used as the private key and is thus vulnerable to offline Brute Force attacks that may expose plaintext credentials.

This same behavior could be executed using service tickets captured from network traffic.

Cracked hashes may enable Persistence, Privilege Escalation, and Lateral Movement via access to Valid Accounts.

Platforms
Windows
Telemetry
WinEventLog:SecurityWinEventLog:Sysmon

How MITRE says to detect it DET0157

Detect Kerberoasting Attempts (T1558.003)

Windows Analytic 0444

Detects Kerberoasting attempts by monitoring for anomalous Kerberos TGS requests (Event ID 4769) with RC4 encryption (etype 0x17), accounts requesting an unusual number of service tickets in a short period, or service accounts targeted outside normal usage baselines. Also correlates suspicious process activity (e.g., Mimikatz invoking LSASS access) with Kerberos ticket anomalies.

  • WinEventLog:Security EventCode=4769
  • WinEventLog:Sysmon EventCode=10
  • WinEventLog:Security EventCode=4624, 4648
  • WinEventLog:Security EventCode=4672

SigmaHQ/sigma

18 rules
Detection Severity Format
HackTool - Rubeus Execution Critical Sigma
DC Machine Account TGS Request from Non-DC Source IP High Sigma
HackTool - KrbRelay Execution High Sigma
HackTool - KrbRelayUp Execution High Sigma
HackTool - RemoteKrbRelay Execution High Sigma
HackTool - Rubeus Execution - ScriptBlock High Sigma
Register new Logon Process by Rubeus High Sigma
Suspicious Kerberos Ticket Request via CLI High Sigma
Suspicious Kerberos Ticket Request via PowerShell Script - ScriptBlock High Sigma
User Couldn't Call a Privileged Service 'LsaRegisterLogonProcess' High Sigma

+ 8 more from SigmaHQ/sigma → showing the 10 highest-severity

elastic/detection-rules

8 rules
Detection Severity Format
Kerberos Cached Credentials Dumping High Elastic TOML
Potential Kerberos Attack via Bifrost High Elastic TOML
PowerShell Kerberos Ticket Request High Elastic TOML
Suspicious Kerberos Authentication Ticket Request High Elastic TOML
Kerberos Traffic from Unusual Process Medium Elastic TOML
Newly Observed RC4 Kerberos Service Ticket Request Medium Elastic TOML
Potential PowerShell HackTool Script by Function Names Medium Elastic TOML
User account exposed to Kerberoasting Medium Elastic TOML

splunk/security_content

8 rules
Detection Severity Format
Kerberoasting spn request with RC4 encryption Undefined SPL
Rubeus Command Line Parameters Undefined SPL
ServicePrincipalNames Discovery with PowerShell Undefined SPL
ServicePrincipalNames Discovery with SetSPN Undefined SPL
Unusual Number of Kerberos Service Tickets Requested Undefined SPL
Windows PowerView Kerberos Service Ticket Request Undefined SPL
Windows PowerView SPN Discovery Undefined SPL
Windows Process With NetExec Command Line Parameters Undefined SPL

Bert-JanP/Hunting-Queries-Detection-Rules

3 rules
Detection Severity Format
Kerberos attacks Undefined KQL
MITRE ATT&CK Mapping Undefined KQL
Potential Kerberos Encryption Downgrade Undefined KQL

elastic/protections-artifacts

1 rule
Detection Severity Format
Potential Kerberos Attack via Bifrost Undefined Elastic TOML

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.