Skip to content
Security

Event ID 4768: Kerberos TGT requested

A Kerberos authentication ticket (TGT) was requestedDomain controller event 4768 records every Kerberos TGT request: the account, client IP, encryption type, pre-authentication type and result.
4768
Event ID
4768
Channel
Security
Provider
Microsoft-Windows-Security-Auditing
Log file
Security.evtx
Category
Kerberos
Default logging
Logged by default

What event 4768 means

Event 4768 is logged by the Key Distribution Center on a domain controller each time an account asks for a Ticket Granting Ticket — the first step of every Kerberos domain logon. User logons, computer startups and services running as domain accounts all generate it.

For forensics it is the DC-side proof that an account authenticated, and from which IP (IpAddress). The TicketEncryptionType and PreAuthType fields expose weak or unusual authentication: RC4 where the domain uses AES, or pre-authentication type 0, meaning the account does not require Kerberos pre-authentication and is exposed to AS-REP roasting.

Failed TGT requests are logged as 4768 with a non-zero Status (for unknown or revoked accounts); a wrong password produces 4771 instead.

When it is logged

Audit policy / configuration

Advanced Audit Policy Configuration > Account Logon > Audit Kerberos Authentication Service (Success, and Failure for failed requests). Only meaningful on domain controllers.

High volume on DCs. Enable Failure auditing explicitly if you want failed requests; check the effective policy with auditpol /get /subcategory:"Kerberos Authentication Service".

Key fields

FieldWhat it tells you
TargetUserNameAccount that requested the TGT (user or computer account ending in $).
TargetDomainNameKerberos realm (domain) supplied by the client.
TargetSidSID of the account, when it exists.
ServiceNameAlways krbtgt for a TGT request.
TicketOptionsKerberos ticket option flags requested (hex), e.g. 0x40810010 for a typical Windows client.
StatusKerberos result code.
ValueMeaning
0x0Success — a TGT was issued.
0x6KDC_ERR_C_PRINCIPAL_UNKNOWN — the user name does not exist.
0x12KDC_ERR_CLIENT_REVOKED — account disabled, expired or locked out.
0x17KDC_ERR_KEY_EXPIRED — the password has expired.
0x25KRB_AP_ERR_SKEW — clock skew too large between client and DC.
TicketEncryptionTypeEncryption type of the issued ticket.
ValueMeaning
0x11AES128-CTS-HMAC-SHA1-96
0x12AES256-CTS-HMAC-SHA1-96 — normal in modern domains.
0x17RC4-HMAC — legacy; suspicious when the account and domain support AES.
0x18RC4-HMAC-EXP
0x1DES-CBC-CRC (disabled by default since Windows 7 / Server 2008 R2).
0x3DES-CBC-MD5 (disabled by default since Windows 7 / Server 2008 R2).
0xffffffffNo ticket issued (failure).
PreAuthTypePre-authentication method used.
ValueMeaning
0No pre-authentication — the account has "Do not require Kerberos preauthentication" set.
2PA-ENC-TIMESTAMP — standard password-based logon.
15PA-PK-AS-REP_OLD — smart card logon.
16PA-PK-AS-REQ — smart card / certificate logon.
138PA-ENCRYPTED-CHALLENGE — Kerberos armoring (FAST).
IpAddressClient IP address (IPv4 addresses may appear as ::ffff:10.0.0.5).
IpPortClient source port.
CertIssuerNameFor certificate logons, the issuing CA — useful when investigating certificate abuse.
CertThumbprintThumbprint of the certificate used for PKINIT logons.

Common benign sources

  • Every domain user and computer logon; computers renew their TGT regularly.
  • Service accounts authenticating when services or scheduled tasks start.
  • Certificate-based (smart card, Windows Hello for Business) logons with PreAuthType 16.

What attackers do that produces it

  • AS-REP roasting — TGT requests with PreAuthType 0 for accounts that do not require pre-authentication, often RC4 (0x17), from a host that is not the user's.
  • A stolen password or hash used from a new IP address — the TGT request is the first DC-side trace.
  • User enumeration against Kerberos — bursts of Status 0x6 for many names from one IP.
  • Certificate abuse (for example certificates obtained through AD CS misconfigurations) shows as PKINIT logons with unexpected CertIssuerName or CertThumbprint.

Investigation tips

  • Build a per-account baseline of client IPs; a TGT for a privileged account from a workstation never used before is a lead.
  • Hunt for PreAuthType 0 and list which accounts have pre-authentication disabled.
  • Flag RC4 (0x17) tickets in domains where AES is standard, then check who requested them.
  • Follow the same account and IP to 4769 (service tickets) to see which services it accessed after authenticating.

MITRE ATT&CK techniques

TechniqueTactics
T1558.004 Steal or Forge Kerberos Tickets: AS-REP RoastingCredential Access
T1078.002 Valid Accounts: Domain AccountsStealth, Persistence, Privilege Escalation, Initial Access
T1110 Brute ForceCredential Access

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

3 SigmaHQ detection rules (release r2026-07-01) target this event.

  • High · 2
  • Medium · 1

Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

In-depth guideEvent ID 4768: Kerberos TGT requests and AS-REP roasting

Sources and further reading