Monitor Windows Event 4769 to detect Kerberoasting attacks, lateral movement, and abnormal service ticket requests. Essential for securing Active Directory environments.
A Kerberos service ticket was requested.
Account Information:
Account Name: jsmith@CONTOSO.COM
Account Domain: CONTOSO.COM
Logon GUID: {a1b2c3d4-...}
Service Information:
Service Name: MSSQLSvc/SQL01.contoso.com:1433
Service ID: S-1-5-21-3398...-1108
Network Information:
Client Address: ::ffff:10.0.5.142
Client Port: 49831
Additional Information:
Ticket Options: 0x40810000
Ticket Encryption Type: 0x17
Failure Code: 0x0