Kerberoasting: bulk service ticket requests with weak encryption
A-106400:00time on this alert, target 10 minutes
Back to queueAlert details
- Source
- SIEM Correlation
- Detection rule
- SIEM-KERBEROAST-003
- Affected user
- m.okafor
- Affected host
- SRV-DC-01
- Source IP
- —
- First seen
- 2026-07-24T17:12:00Z
Why this fired, in plain English
One account asked for lots of service tickets using old, weak encryption. Attackers do this so they can crack service passwords offline.
Suggested playbook
Privilege escalation
- 1. Establish scope: local group (4732) or domain group (4728)?
- 2. Check for an approved change ticket or helpdesk ticket covering the grant.
- 3. Check whether the rights were later removed (4733/4729) — clean-up suggests legitimate work.
- 4. Identify who performed the action and from which host and IP.
Raw log evidence
Exactly what the tools recorded — 3 events.
Guided hint: this line matters
ts=2026-07-24T17:10:04Z host=SRV-DC-01 EventID=4769 account="m.okafor" service="MSSQLSvc/SRV-ERP-02" ticket_encryption=0x17 src_ip=10.20.14.61 status=0x0
Encryption type 0x17 is RC4, the weak legacy option attackers request because it is easy to crack.
ts=2026-07-24T17:10:05Z host=SRV-DC-01 EventID=4769 account="m.okafor" service="HTTP/SRV-FILE-03" ticket_encryption=0x17 src_ip=10.20.14.61 status=0x0
Guided hint: this line matters
ts=2026-07-24T17:10:09Z host=SRV-DC-01 EventID=4769 account="m.okafor" distinct_services=27 window_sec=6 ticket_encryption=0x17
27 different service tickets in six seconds is scripted harvesting, not normal application use.
Related events
The order things happened in.
17:10Z
27 RC4 service tickets requested in 6 seconds
17:12Z
Kerberoasting correlation fires
Enrichment lookups
Mock lookups. Run each one yourself — a real analyst never guesses what a lookup would have said. There is no "run everything" button on purpose.
Not checked yet.
Not checked yet.
Not checked yet.
Not checked yet.
techniques
Your verdict
Keyboard shortcuts 1–4, or click. You can always change your mind afterwards.