Windows Kerberos Service Tickets Requesting RC4 Encryption (EventID 4769)

Flags Windows Kerberos service ticket requests using RC4 encryption while excluding '$' machine/service accounts.

FreeReviewedSigma · Medium · v2
Product
windows
Service
security
Author
Florian Roth (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2017-02-06
Updated
2026-07-31

ATT&CK techniques

Cred Access
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule flags Kerberos service ticket requests that specify RC4 as the ticket encryption type and match a particular TicketOptions value. Attackers may use weaker or targeted encryption settings to facilitate credential access attempts such as offline cracking of extracted ticket material. It relies on Windows Security auditing telemetry for EventID 4769, including TicketOptions, TicketEncryptionType, and ServiceName to suppress likely benign machine-account behavior.

Related detections9 linkedT1558.003 — drag to rearrange
Malicious Kerberos Ticket File Creation Indicating Credential Theft (via file_event)
Suspicious Kerberoasting via setspn Service Principal Query
Masquerading Kerberos Ticket Abuse via Rubeus (via process_creation)
Possible Targeted Kerberoasting via servicePrincipalName Modification
Suspicious SQL Service Principal Name Enumeration via Setspn
Windows: Suspicious Kerberos Ticket Requests from PowerShell Using KerberosRequestorSecurityToken
Windows Process Creation: RemoteKrbRelay Kerberos Relay Tool Execution
Windows Kerberos KDC Key Distribution Failure: No Suitable Encryption Key or Unsupported EType
Rubeus HackTool Execution via PowerShell ScriptBlock Flags (Windows)
Windows Kerberos Service Tickets Requesting RC4 Encryption (EventID 4769)
Pivot detection · T1558.003 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.