CompTIA CySA+ (CS0-003)Security OperationsHard

An analyst investigating suspected credential abuse filters Windows Security Event Logs for Kerberos service ticket requests and finds a large number of Event ID 4769 entries for a single user account, all requesting tickets with RC4 encryption (etype 0x17) for multiple different service accounts within a short time span. Which attack technique does this pattern MOST likely indicate?

  1. AKerberoasting
  2. BGolden ticket forgery
  3. CLLMNR poisoning
  4. DPass-the-hash attack
Show answer & explanation

Correct answer: A. Kerberoasting

Kerberoasting involves requesting TGS (service) tickets for multiple SPNs, often forcing weaker RC4 encryption (etype 0x17) because it's easier to crack offline than AES. A burst of 4769 events for one account against many service accounts is the classic signature.

Why the other options are wrong

  • B. Golden ticket forgery involves forged TGTs using a stolen krbtgt hash, typically seen as anomalous TGT (4768) or logon anomalies, not a burst of 4769 RC4 TGS requests.
  • C. LLMNR poisoning targets name resolution broadcasts, unrelated to Kerberos ticket requests.
  • D. Pass-the-hash uses NTLM hash reuse for authentication, not TGS ticket requests logged as 4769.

Kerberoasting

An attack where an authenticated user requests TGS tickets for service accounts with SPNs, then attempts to crack the ticket's encrypted portion offline to recover the service account password.

  • Logged as Event ID 4769 (Kerberos Service Ticket Request)
  • Attackers often force RC4 (etype 0x17) since it's weaker/faster to crack
  • Mitigated by using AES-only accounts and strong service account passwords

Memory trick: Kerberoasting = 'roasting' many service tickets over an RC4 fire to crack passwords later.

More Security Operations questions