Cross-source coverage
T1558.003 / ATT&CK
Steal or Forge Kerberos Tickets: Kerberoasting
From MITRE ATT&CK 19.2
Adversaries may abuse a valid Kerberos ticket-granting ticket (TGT) or sniff network traffic to obtain a ticket-granting service (TGS) ticket that may be vulnerable to Brute Force.
Service principal names (SPNs) are used to uniquely identify each instance of a Windows service. To enable authentication, Kerberos requires that SPNs be associated with at least one service logon account (an account specifically tasked with running a service).
Adversaries possessing a valid Kerberos ticket-granting ticket (TGT) may request one or more Kerberos ticket-granting service (TGS) service tickets for any SPN from a domain controller (DC). Portions of these tickets may be encrypted with the RC4 algorithm, meaning the Kerberos 5 TGS-REP etype 23 hash of the service account associated with the SPN is used as the private key and is thus vulnerable to offline Brute Force attacks that may expose plaintext credentials.
This same behavior could be executed using service tickets captured from network traffic.
Cracked hashes may enable Persistence, Privilege Escalation, and Lateral Movement via access to Valid Accounts.
- Tactics
- Credential Access
- Platforms
- Windows
- Telemetry
-
WinEventLog:SecurityWinEventLog:Sysmon
How MITRE says to detect it DET0157
Detect Kerberoasting Attempts (T1558.003)
Windows Analytic 0444
Detects Kerberoasting attempts by monitoring for anomalous Kerberos TGS requests (Event ID 4769) with RC4 encryption (etype 0x17), accounts requesting an unusual number of service tickets in a short period, or service accounts targeted outside normal usage baselines. Also correlates suspicious process activity (e.g., Mimikatz invoking LSASS access) with Kerberos ticket anomalies.
WinEventLog:SecurityEventCode=4769WinEventLog:SysmonEventCode=10WinEventLog:SecurityEventCode=4624, 4648WinEventLog:SecurityEventCode=4672
SigmaHQ/sigma
18 rules| Detection | Severity | Format |
|---|---|---|
| HackTool - Rubeus Execution | Critical | Sigma |
| DC Machine Account TGS Request from Non-DC Source IP | High | Sigma |
| HackTool - KrbRelay Execution | High | Sigma |
| HackTool - KrbRelayUp Execution | High | Sigma |
| HackTool - RemoteKrbRelay Execution | High | Sigma |
| HackTool - Rubeus Execution - ScriptBlock | High | Sigma |
| Register new Logon Process by Rubeus | High | Sigma |
| Suspicious Kerberos Ticket Request via CLI | High | Sigma |
| Suspicious Kerberos Ticket Request via PowerShell Script - ScriptBlock | High | Sigma |
| User Couldn't Call a Privileged Service 'LsaRegisterLogonProcess' | High | Sigma |
+ 8 more from SigmaHQ/sigma → showing the 10 highest-severity
elastic/detection-rules
8 rules| Detection | Severity | Format |
|---|---|---|
| Kerberos Cached Credentials Dumping | High | Elastic TOML |
| Potential Kerberos Attack via Bifrost | High | Elastic TOML |
| PowerShell Kerberos Ticket Request | High | Elastic TOML |
| Suspicious Kerberos Authentication Ticket Request | High | Elastic TOML |
| Kerberos Traffic from Unusual Process | Medium | Elastic TOML |
| Newly Observed RC4 Kerberos Service Ticket Request | Medium | Elastic TOML |
| Potential PowerShell HackTool Script by Function Names | Medium | Elastic TOML |
| User account exposed to Kerberoasting | Medium | Elastic TOML |
splunk/security_content
8 rules| Detection | Severity | Format |
|---|---|---|
| Kerberoasting spn request with RC4 encryption | Undefined | SPL |
| Rubeus Command Line Parameters | Undefined | SPL |
| ServicePrincipalNames Discovery with PowerShell | Undefined | SPL |
| ServicePrincipalNames Discovery with SetSPN | Undefined | SPL |
| Unusual Number of Kerberos Service Tickets Requested | Undefined | SPL |
| Windows PowerView Kerberos Service Ticket Request | Undefined | SPL |
| Windows PowerView SPN Discovery | Undefined | SPL |
| Windows Process With NetExec Command Line Parameters | Undefined | SPL |
Bert-JanP/Hunting-Queries-Detection-Rules
3 rules| Detection | Severity | Format |
|---|---|---|
| Kerberos attacks | Undefined | KQL |
| MITRE ATT&CK Mapping | Undefined | KQL |
| Potential Kerberos Encryption Downgrade | Undefined | KQL |
elastic/protections-artifacts
1 rule| Detection | Severity | Format |
|---|---|---|
| Potential Kerberos Attack via Bifrost | Undefined | Elastic TOML |