Windows Kerberos TGT Issue Operations Failures (Event IDs 675/4768/4769/4771)

Alerts on Windows Security failures for Kerberos TGT-related operations using specific Kerberos event IDs and status codes.

FreeReviewedSigma · High · v2
Product
windows
Service
security
Author
Florian Roth (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2017-02-10
Updated
2026-07-31

ATT&CK techniques

Cred Access
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule flags Windows Security events indicating failed Kerberos Ticket-Granting Ticket (TGT) issue operations, based on matching Event IDs 675, 4768, 4769, and 4771 together with specific failure statuses. Attackers may manipulate Kerberos TGT-related messages or attempt authentication flows to disrupt or obtain tickets, and repeated failures can be a useful indicator. The detection relies on Windows Security log telemetry with these event IDs and the enumerated status codes.

Related detections4 linkedT1212 — drag to rearrange
Windows Rundll32 Calls DavSetCookie for NTLM Coercion via Spoolss/Srvsvc
Apache Guacamole Linux: Two-User Session Presence Anomaly
Windows Process Creation alerts on GALLIUM-associated hash IOCs
Windows Audit-CVE: User Applications Writing CveEventWrite Events (Event ID 1)
Windows Kerberos TGT Issue Operations Failures (Event IDs 675/4768/4769/4771)
Pivot detection · T1212 · 4 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.