Event ID 4768: Kerberos TGT requested
- Event ID
- 4768
- Channel
- Security
- Provider
- Microsoft-Windows-Security-Auditing
- Log file
- Security.evtx
- Category
- Kerberos
- Default logging
- Logged by default
What event 4768 means
Event 4768 is logged by the Key Distribution Center on a domain controller each time an account asks for a Ticket Granting Ticket — the first step of every Kerberos domain logon. User logons, computer startups and services running as domain accounts all generate it.
For forensics it is the DC-side proof that an account authenticated, and from which IP (IpAddress). The TicketEncryptionType and PreAuthType fields expose weak or unusual authentication: RC4 where the domain uses AES, or pre-authentication type 0, meaning the account does not require Kerberos pre-authentication and is exposed to AS-REP roasting.
Failed TGT requests are logged as 4768 with a non-zero Status (for unknown or revoked accounts); a wrong password produces 4771 instead.
When it is logged
Advanced Audit Policy Configuration > Account Logon > Audit Kerberos Authentication Service (Success, and Failure for failed requests). Only meaningful on domain controllers.
High volume on DCs. Enable Failure auditing explicitly if you want failed requests; check the effective policy with auditpol /get /subcategory:"Kerberos Authentication Service".
Key fields
| Field | What it tells you | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| TargetUserName | Account that requested the TGT (user or computer account ending in $). | ||||||||||||||||
| TargetDomainName | Kerberos realm (domain) supplied by the client. | ||||||||||||||||
| TargetSid | SID of the account, when it exists. | ||||||||||||||||
| ServiceName | Always krbtgt for a TGT request. | ||||||||||||||||
| TicketOptions | Kerberos ticket option flags requested (hex), e.g. 0x40810010 for a typical Windows client. | ||||||||||||||||
| Status | Kerberos result code.
| ||||||||||||||||
| TicketEncryptionType | Encryption type of the issued ticket.
| ||||||||||||||||
| PreAuthType | Pre-authentication method used.
| ||||||||||||||||
| IpAddress | Client IP address (IPv4 addresses may appear as ::ffff:10.0.0.5). | ||||||||||||||||
| IpPort | Client source port. | ||||||||||||||||
| CertIssuerName | For certificate logons, the issuing CA — useful when investigating certificate abuse. | ||||||||||||||||
| CertThumbprint | Thumbprint of the certificate used for PKINIT logons. |
Common benign sources
- Every domain user and computer logon; computers renew their TGT regularly.
- Service accounts authenticating when services or scheduled tasks start.
- Certificate-based (smart card, Windows Hello for Business) logons with PreAuthType 16.
What attackers do that produces it
- AS-REP roasting — TGT requests with PreAuthType
0for accounts that do not require pre-authentication, often RC4 (0x17), from a host that is not the user's. - A stolen password or hash used from a new IP address — the TGT request is the first DC-side trace.
- User enumeration against Kerberos — bursts of Status
0x6for many names from one IP. - Certificate abuse (for example certificates obtained through AD CS misconfigurations) shows as PKINIT logons with unexpected CertIssuerName or CertThumbprint.
Investigation tips
- Build a per-account baseline of client IPs; a TGT for a privileged account from a workstation never used before is a lead.
- Hunt for PreAuthType 0 and list which accounts have pre-authentication disabled.
- Flag RC4 (
0x17) tickets in domains where AES is standard, then check who requested them. - Follow the same account and IP to 4769 (service tickets) to see which services it accessed after authenticating.
MITRE ATT&CK techniques
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
3 SigmaHQ detection rules (release r2026-07-01) target this event.
- High · 2
- Medium · 1
- HighKerberos ManipulationRule by Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
- HighPetitPotam Suspicious Kerberos TGT RequestRule by Mauricio Velazco, Michael Haag, SigmaHQ, DRL 1.1
- MediumPotential AS-REP Roasting via Kerberos TGT RequestsRule by ANosir, SigmaHQ, DRL 1.1
Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.