Windows Kerberos Replay Attack Likely Activity on Domain Controllers (Event ID 4649)

Alerts on Windows Security Event 4649 indicating a Kerberos replay error (KRB_AP_ERR_REPEAT).

FreeReviewedSigma · High · v2
Product
windows
Service
security
Author
frack113 (SigmaHQ), DRL 1.1
Published
2022-10-14
Updated
2026-07-31

ATT&CK techniques

Cred Access
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule flags Windows Security audit events on domain controllers where a Kerberos response indicating KRB_AP_ERR_REPEAT is logged (Event ID 4649). An attacker may use replayed Kerberos authentication messages to bypass freshness checks and attempt credential abuse. The detection relies on the presence of the specific Kerberos replay-related event captured in Windows Security logs.

Related detections8 linkedT1558 — drag to rearrange
Malicious Kerberos proxiable/S4U2self Ticket - CVE-2021-42278/42287 (via security)
Malicious Rubeus Kerberos Unconstrained Delegation Abuse (via security)
Malicious Rubeus Kerberos Constrained Delegation Abuse - S4U2Proxy (via security)
Renamed Mimikatz Credential Theft Command Indicators (via process_creation)
Windows PowerShell ScriptBlock: Get-ADComputer reconnaissance for unconstrained delegation properties
Windows HackTool Activity: Mimikatz Kerberos Ticket and MemSSP File Creation
Windows: Uncommon Outbound Kerberos Traffic on Port 88
Antivirus Credential Dumping Signature Match (Password Dumpers/Stealers)
Windows Kerberos Replay Attack Likely Activity on Domain Controllers (Event ID 4649)
Pivot detection · T1558 · 8 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.