Windows Security: Kerberos TGT requests with PreAuthType=0 and RC4-HMAC (0x17) to krbtgt

Alerts on krbtgt TGT requests using RC4-HMAC with pre-authentication disabled (PreAuthType=0), consistent with AS-REP roasting attempts.

FreeReviewedSigma · Medium · v2
Product
windows
Service
security
Author
ANosir (SigmaHQ), DRL 1.1
Published
2025-05-22
Updated
2026-07-31

What it detects

This rule flags Windows Security events where Kerberos TGT requests are made to the krbtgt service with pre-authentication disabled (PreAuthType=0) and Ticket Encryption Type set to 0x17 (RC4-HMAC). Disabling pre-authentication and using RC4-HMAC can allow attackers to obtain ticket material that may be subjected to offline password guessing. It relies on Security event telemetry (EventID 4768) and the event fields ServiceName, PreAuthType, and TicketEncryptionType.

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.