Detection rules › By event
Microsoft-Windows-Security-Auditing event 4768
Sigma (3)
Splunk (10)
- Kerberos TGT Request Using RC4 Encryption
- Kerberos User Enumeration
- PetitPotam Suspicious Kerberos TGT Request
- Suspicious Ticket Granting Ticket Request
- Windows Computer Account Requesting Kerberos Ticket
- Windows Multiple Disabled Users Failed To Authenticate Wth Kerberos
- Windows Multiple Invalid Users Fail To Authenticate Using Kerberos
- Windows Steal Authentication Certificates - ESC1 Authentication
- Windows Unusual Count Of Disabled Users Failed Auth Using Kerberos
- Windows Unusual Count Of Invalid Users Fail To Auth Using Kerberos