A security analyst is investigating an alert from Microsoft Defender for Identity indicating 'Suspicious Kerberos ticket request (Golden Ticket)'. To confirm this activity and gather more context, the analyst needs to query the raw Kerberos authentication events, specifically looking for successful Kerberos service ticket requests. Which Kusto Query Language (KQL) query should the analyst use to retrieve events with Event ID 4769 from the appropriate Advanced Hunting table?
- ADeviceProcessEvents | where ProcessCommandLine contains 'kerb' and EventId == 4769
- BIdentityLogonEvents | where ActionType == 'KerberosTicketRequest' and Protocol == 'Kerberos' and EventId == 4769
- CDeviceLogonEvents | where ActionType == 'Logon' and Protocol == 'Kerberos' and EventId == 4769
- DIdentityLogonEvents | where Protocol == 'Kerberos' and EventId == 4769
Show answer & explanationAnswer & explanation
Correct answer: D. IdentityLogonEvents | where Protocol == 'Kerberos' and EventId == 4769
Event ID 4769 specifically refers to a successful Kerberos service ticket request. The 'IdentityLogonEvents' table is the correct Advanced Hunting table for querying identity-related logon and authentication activities, including Kerberos events. While 'ActionType == 'KerberosTicketRequest'' is a valid filter for this specific action, simply filtering by 'Protocol == 'Kerberos' and EventId == 4769' is more direct and accurate as Event ID 4769 uniquely identifies this specific Kerberos event. Option B is redundant and potentially less robust if the ActionType string changes slightly but the EventId remains constant. Option C is the most concise and accurate for the given Event ID.
Why the other options are wrong
- A. DeviceProcessEvents is for process activity, and filtering by command line is not the proper way to find specific Kerberos authentication events.
- B. While partially correct, 'ActionType == 'KerberosTicketRequest'' is often inferred from EventId 4769, making the ActionType filter redundant and potentially less reliable than directly using the Event ID.
- C. DeviceLogonEvents is for device logons, not specific Kerberos service ticket requests captured by Defender for Identity.
Kerberos Event ID 4769
Windows Security Event ID 4769 signifies 'A Kerberos service ticket was requested.' It is a crucial event for detecting Kerberos-related attacks like Golden Ticket or Silver Ticket.
- Indicates a successful Kerberos service ticket request.
- Monitored by Microsoft Defender for Identity for suspicious activity.
- Found in the 'IdentityLogonEvents' table in Advanced Hunting.
Memory trick: Identity logon events for Kerberos tickets.