A security analyst is building a detection for Kerberoasting in the SIEM using Windows Security event logs. Which Event ID indicates that a Kerberos service ticket was requested for an account with an SPN?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — b is correct because Event ID 4769 records Kerberos service ticket requests; Kerberoasting specifically requests tickets encrypted with RC4 (encryption type 0x17) because RC4-encrypted tickets are easier to crack offline; filtering 4769 for RC4 encryption against high-value accounts is the standard Kerberoasting detection. A is wrong because Event ID 4768 records TGT (Ticket Granting Ticket) requests, not service ticket requests; Kerberoasting targets service tickets specifically.
Full explanation below image
Full Explanation
B is correct because Event ID 4769 records Kerberos service ticket requests; Kerberoasting specifically requests tickets encrypted with RC4 (encryption type 0x17) because RC4-encrypted tickets are easier to crack offline; filtering 4769 for RC4 encryption against high-value accounts is the standard Kerberoasting detection. A is wrong because Event ID 4768 records TGT (Ticket Granting Ticket) requests, not service ticket requests; Kerberoasting targets service tickets specifically. C is wrong because Event ID 4771 records pre-authentication failures, which occur during password spraying or brute-force against Kerberos, not Kerberoasting. D is wrong because Event ID 4648 records the use of explicit alternate credentials in a logon, not Kerberos ticket operations.