Windows Kerberos KDC: Certificate used without strong user mapping

Alerts on Windows KDC certificate validation events lacking strong certificate-to-user mapping (Event 39/41).

FreeReviewedSigma · Medium · v2
Product
windows
Service
system
Author
@br4dy5 (SigmaHQ), DRL 1.1
Published
2023-10-09
Updated
2026-07-31

What it detects

This rule flags Windows Kerberos Key Distribution Center (KDC) events where a valid certificate cannot be strongly mapped to a user, such as via explicit mapping, key trust mapping, or SID mapping. Attackers may rely on weak or missing mapping to impersonate identities or abuse certificate-based authentication paths. It uses Windows System telemetry from the KDC for Event IDs 39 and 41 and matches based on the Kerberos-Key-Distribution-Center provider names.

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.