Windows System: Kerberos KDC RC4-HMAC downgrade exploit attempts (CVE-2022-37966)

Identifies Windows Kerberos KDC error events tied to RC4-HMAC downgrade/auth negotiation exploitation behavior (CVE-2022-37966).

FreeReviewedSigma · High · v5
Product
windows
Service
system
Author
Florian Roth (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2022-11-09
Updated
2026-07-31

What it detects

This rule flags error-level Kerberos Key Distribution Center (KDC) events that match Kerberos key distribution activity consistent with an RC4-HMAC negotiation downgrade and authentication bypass leading to privilege escalation. Attackers may leverage weak RC4-HMAC negotiation to trigger a security bypass and elevate privileges on Windows environments. The detection relies on Windows System logs for EventID 42 emitted by the Kerberos Key Distribution Center providers.

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.