What it does. Detect Kerberoasting attacks by monitoring for anomalous Kerberos TGS Part of mukul975/Anthropic-Cybersecurity-Skills (817 security skills) (mukul975/Anthropic-Cybersecurity-Skills).
Install
npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill detecting-kerberoasting-attacks, or copy the skill folder into ~/.claude/skills/detecting-kerberoasting-attacks/.
- Raw file:
curl -sL https://raw.githubusercontent.com/mukul975/Anthropic-Cybersecurity-Skills/HEAD/skills/detecting-kerberoasting-attacks/SKILL.md
SKILL.md (verbatim)
name: detecting-kerberoasting-attacks
description: Detect Kerberoasting attacks by monitoring for anomalous Kerberos TGS
requests (Event ID 4769) targeting service accounts with SPNs, which attackers request
offline to crack service account passwords. Use when hunting for MITRE T1558 credential
access activity or investigating suspected service account password cracking attempts
in Active Directory Kerberos logs.
domain: cybersecurity
subdomain: threat-hunting
tags:
- threat-hunting
- mitre-attack
- kerberoasting
- credential-access
- kerberos
- t1558
- proactive-detection
version: '1.0'
author: mahipal
license: Apache-2.0
d3fend_techniques:
- Application Protocol Command Analysis
- Network Isolation
- Network Traffic Analysis
- Client-server Payload Profiling
- Network Traffic Community Deviation
nist_csf:
- DE.CM-01
- DE.AE-02
- DE.AE-07
- ID.RA-05
mitre_attack:
- T1046
- T1057
- T1082
- T1083
- T1003
Detecting Kerberoasting Attacks
When to Use
- When proactively hunting for indicators of detecting kerberoasting attacks in the environment
- After threat intelligence indicates active campaigns using these techniques
- During incident response to scope compromise related to these techniques
- When EDR or SIEM alerts trigger on related indicators
- During periodic security assessments and purple team exercises
Prerequisites
- EDR platform with process and network telemetry (CrowdStrike, MDE, SentinelOne)
- SIEM with relevant log data ingested (Splunk, Elastic, Sentinel)
- Sysmon deployed with comprehensive configuration
- Windows Security Event Log forwarding enabled
- Threat intelligence feeds for IOC correlation
Workflow
- Formulate Hypothesis: Define a testable hypothesis based on threat intelligence or ATT&CK gap analysis.
- Identify Data Sources: Determine which logs and telemetry are needed to validate or refute the hypothesis.
- Execute Queries: Run detection queries against SIEM and EDR platforms to collect relevant events.
- Analyze Results: Examine query results for anomalies, correlating across multiple data sources.
- Validate Findings: Distinguish true positives from false positives through contextual analysis.
- Correlate Activity: Link findings to broader attack chains and threat actor TTPs.
- Document and Report: Record findings, update detection rules, and recommend response actions.
Key Concepts
| Concept |
Description |
| T1558.003 |
Kerberoasting |
| T1558.004 |
AS-REP Roasting |
| T1558.001 |
Golden Ticket |
| Tool |
Purpose |
| CrowdStrike Falcon |
EDR telemetry and threat detection |
| Microsoft Defender for Endpoint |
Advanced hunting with KQL |
| Splunk Enterprise |
SIEM log analysis with SPL queries |
| Elastic Security |
Detection rules and investigation timeline |
| Sysmon |
Detailed Windows event monitoring |
| Velociraptor |
Endpoint artifact collection and hunting |
| Sigma Rules |
Cross-platform detection rule format |
Common Scenarios
- Scenario 1: Rubeus kerberoast targeting all SPN accounts
- Scenario 2: GetUserSPNs.py from Impacket requesting RC4 tickets
- Scenario 3: Targeted kerberoast against high-privilege service accounts
- Scenario 4: AS-REP roasting accounts without pre-authentication
Hunt ID: TH-DETECT-[DATE]-[SEQ]
Technique: T1558.003
Host: [Hostname]
User: [Account context]
Evidence: [Log entries, process trees, network data]
Risk Level: [Critical/High/Medium/Low]
Confidence: [High/Medium/Low]
Recommended Action: [Containment, investigation, monitoring]
Other files in this skill
assets/template.md (verbatim)
Detecting Kerberoasting Attacks - Hunt Template
| Field |
Value |
| Hunt ID |
TH-DETECT-YYYY-MM-DD-NNN |
| Analyst |
|
| Date Started |
|
| Date Completed |
|
| Status |
[ ] In Progress / [ ] Complete |
| Priority |
[ ] Critical / [ ] High / [ ] Medium / [ ] Low |
Hypothesis
Statement: [Formulate a clear, testable hypothesis]
Basis: [ ] Threat Intel / [ ] ATT&CK Gap / [ ] Anomaly / [ ] Incident Follow-up
Target Techniques
Data Sources
Queries Executed
Query 1: [Description]
[Query text]
Results: [Count] events | Execution Time: [Duration]
Query 2: [Description]
[Query text]
Results: [Count] events | Execution Time: [Duration]
Findings
| # |
Timestamp |
Host |
User |
Technique |
Evidence Summary |
Risk |
Verdict |
| 1 |
|
|
|
|
|
|
TP / FP / BTP |
| 2 |
|
|
|
|
|
|
TP / FP / BTP |
| 3 |
|
|
|
|
|
|
TP / FP / BTP |
IOCs Discovered
Network IOCs
| Type |
Value |
Context |
Confidence |
| IP |
|
|
|
| Domain |
|
|
|
| URL |
|
|
|
Host IOCs
| Type |
Value |
Context |
Confidence |
| SHA256 |
|
|
|
| Filename |
|
|
|
| Registry Key |
|
|
|
| Scheduled Task |
|
|
|
Hunt Results Summary
| Metric |
Count |
| Total Events Analyzed |
|
| Anomalies Identified |
|
| True Positives |
|
| False Positives |
|
| Benign True Positives |
|
| New IOCs Discovered |
|
| Detection Rules Created |
|
| Detection Rules Updated |
|
Hypothesis Outcome
Recommendations
- Immediate Actions: [Containment, remediation steps]
- Detection Improvements: [New rules, tuning recommendations]
- Visibility Gaps: [Missing data sources, coverage needs]
- Security Hardening: [Configuration changes, policy updates]
- Follow-up Hunts: [Related hypotheses to investigate]
Analyst Notes
[Free-form notes, observations, and lessons learned]
references/api-reference.md (verbatim)
API Reference: Detecting Kerberoasting Attacks
python-evtx Library
from Evtx.Evtx import FileHeader
with open("Security.evtx", "rb") as f:
fh = FileHeader(f)
for record in fh.records():
xml_string = record.xml()
Event ID 4769 - Kerberos TGS Request
<EventData>
<Data Name="TargetUserName">svc_sql</Data>
<Data Name="ServiceName">MSSQLSvc/db01.corp.local:1433</Data>
<Data Name="TicketEncryptionType">0x17</Data>
<Data Name="TicketOptions">0x40810000</Data>
<Data Name="IpAddress">::ffff:10.0.0.50</Data>
<Data Name="Status">0x0</Data>
</EventData>
Encryption Type Values
| Hex |
Type |
Risk |
| 0x17 |
RC4-HMAC |
Kerberoasting indicator |
| 0x18 |
RC4-HMAC-EXP |
Kerberoasting indicator |
| 0x11 |
AES128-CTS-HMAC-SHA1 |
Normal |
| 0x12 |
AES256-CTS-HMAC-SHA1 |
Normal |
Detection Logic
- Filter Event 4769 where TicketEncryptionType = 0x17 (RC4)
- Exclude machine accounts (ServiceName ending in
$)
- Exclude krbtgt service
- Alert on high-volume TGS from single source (>10 unique SPNs in 5 min)
- Correlate with Event 4624 for source attribution
Event ID 4624 - Logon Event (Correlation)
<Data Name="TargetUserName">attacker_user</Data>
<Data Name="LogonType">3</Data>
<Data Name="IpAddress">10.0.0.50</Data>
<Data Name="WorkstationName">WORKSTATION1</Data>
MITRE ATT&CK Mapping
- T1558.003 - Kerberoasting
- T1558 - Steal or Forge Kerberos Tickets
references/standards.md (verbatim)
Standards and References - Detecting Kerberoasting Attacks
MITRE ATT&CK Mappings
| Technique |
Name |
Description |
| T1558.003 |
Kerberoasting |
See attack.mitre.org/techniques/T1558/003 |
| T1558.004 |
AS-REP Roasting |
See attack.mitre.org/techniques/T1558/004 |
| T1558.001 |
Golden Ticket |
See attack.mitre.org/techniques/T1558/001 |
Detection Data Sources
| Source |
Event ID |
Purpose |
| Sysmon |
1 |
Process creation with command line |
| Sysmon |
3 |
Network connection initiated |
| Sysmon |
7 |
Image loaded (DLL) |
| Sysmon |
10 |
Process access (LSASS) |
| Sysmon |
11 |
File creation |
| Sysmon |
12/13 |
Registry create/set |
| Sysmon |
22 |
DNS query |
| Sysmon |
25 |
Process tampering |
| Windows Security |
4624 |
Successful logon |
| Windows Security |
4625 |
Failed logon |
| Windows Security |
4648 |
Explicit credential logon |
| Windows Security |
4672 |
Special privileges assigned |
| Windows Security |
4688 |
Process creation |
| Windows Security |
4697 |
Service installed |
| Windows Security |
4698 |
Scheduled task created |
| Windows Security |
4769 |
Kerberos TGS requested |
| Windows Security |
5140 |
Network share accessed |
References
references/workflows.md (verbatim)
Detailed Hunting Workflow - Detecting Kerberoasting Attacks
Phase 1: Data Collection and Querying
Splunk SPL Query
index=wineventlog EventCode=4769 Ticket_Encryption_Type=0x17
| where Service_Name!="krbtgt" AND NOT match(Service_Name, "\\$")
| stats count dc(Service_Name) as unique_services by Account_Name Client_Address
| where unique_services > 5
| sort -unique_services
KQL Query (Microsoft Defender for Endpoint)
SecurityEvent
| where EventID == 4769
| where TicketEncryptionType == "0x17"
| where ServiceName !endswith "$" and ServiceName != "krbtgt"
| summarize ServiceCount=dcount(ServiceName), Services=make_set(ServiceName) by SubjectUserName, IpAddress
| where ServiceCount > 5
Phase 2: Baseline and Anomaly Detection
Step 2.1 - Establish Normal Behavior Baseline
- Collect 30 days of historical data for the targeted technique
- Document expected patterns, frequencies, and legitimate use cases
- Identify known false positive sources and document exceptions
- Build statistical baseline (mean, standard deviation) for key metrics
Step 2.2 - Identify Anomalies
- Compare current activity against the 30-day baseline
- Flag events exceeding 3 standard deviations from normal
- Prioritize anomalies by risk score and potential business impact
- Cross-reference with threat intelligence for known IOCs
Phase 3: Investigation and Correlation
Step 3.1 - Deep Dive Analysis
- For each anomaly, collect full process tree context
- Correlate with network activity, file operations, and authentication events
- Check binary signatures, file hashes, and certificate validity
- Review user account context and access patterns
Step 3.2 - Attack Chain Reconstruction
- Map findings to MITRE ATT&CK kill chain stages
- Identify initial access vector if applicable
- Trace lateral movement and privilege escalation paths
- Determine data access and potential exfiltration
Phase 4: Validation and Response
Step 4.1 - True/False Positive Determination
- Verify findings with system owners and IT operations
- Check change management records for authorized activities
- Validate user context (authorized actions vs. compromised account)
- Document determination rationale for each finding
Step 4.2 - Response Actions
- For confirmed threats: initiate incident response procedures
- For detection gaps: create or update detection rules
- For false positives: tune existing rules and update exclusions
- Update threat hunting playbook with lessons learned
Phase 5: Documentation and Reporting
Step 5.1 - Hunt Report
- Summarize hypothesis, methodology, and findings
- Include all queries executed and their results
- Document IOCs discovered and detection rules created
- Provide recommendations for security improvements
Step 5.2 - Knowledge Base Update
- Add findings to threat intelligence platform
- Update MITRE ATT&CK coverage heatmap
- Share detection rules via Sigma format
- Schedule follow-up hunts for related techniques
Back to mukul975/Anthropic-Cybersecurity-Skills (817 security skills) or Agent skills.