Skip to content
Security

Event ID 4769: Kerberos service ticket requested

A Kerberos service ticket was requestedEvent 4769 is logged on domain controllers for every Kerberos service ticket (TGS) request — the key record for spotting Kerberoasting.
4769
Event ID
4769
Channel
Security
Provider
Microsoft-Windows-Security-Auditing
Log file
Security.evtx
Category
Kerberos
Default logging
Logged by default

What event 4769 means

Event 4769 is written by the KDC on a domain controller when an account that already holds a TGT asks for a ticket to a specific service (a Ticket Granting Service request). Every access to a Kerberos-protected resource — file shares, SQL Server, HTTP with Windows authentication, LDAP, other hosts — produces one.

The ServiceName field shows which service account the ticket is for, and TicketEncryptionType shows how it is encrypted. That combination is how Kerberoasting is found: an attacker requests tickets for user accounts that have an SPN, preferably RC4-encrypted (0x17) because they crack faster offline. Requests like that for many services in a short time, from one account, are the classic signature.

Volume is very high on DCs. Exclude computer accounts (ServiceName ending in $) and krbtgt before hunting.

When it is logged

Audit policy / configuration

Advanced Audit Policy Configuration > Account Logon > Audit Kerberos Service Ticket Operations (Success, Failure). Only meaningful on domain controllers.

Check the effective policy with auditpol /get /subcategory:"Kerberos Service Ticket Operations"; Failure auditing is often not enabled.

Key fields

FieldWhat it tells you
TargetUserNameAccount that requested the service ticket, in user@DOMAIN form.
TargetDomainNameDomain of the requesting account.
ServiceNameAccount that runs the service the ticket is for. Computer accounts end in $; a user account here means a service with an SPN on a user — a Kerberoasting target.
ServiceSidSID of the service account.
TicketOptionsKerberos ticket options requested (hex).
TicketEncryptionTypeEncryption type of the service ticket.
ValueMeaning
0x11AES128-CTS-HMAC-SHA1-96
0x12AES256-CTS-HMAC-SHA1-96
0x17RC4-HMAC — the type Kerberoasting tools ask for.
0x18RC4-HMAC-EXP
0xffffffffNo ticket issued (failure).
StatusKerberos result code; 0x0 means the ticket was issued.
IpAddressClient IP address.
IpPortClient source port.
LogonGuidGUID linking this request to the logon (the same GUID appears in the 4624 on the target server).
TransmittedServicesServices involved in delegation (constrained delegation / S4U), otherwise -.

Common benign sources

  • Normal access to file servers, SQL, IIS and other Kerberos services — thousands per hour on busy DCs.
  • Computers requesting tickets to DCs (LDAP, CIFS) for Group Policy processing.
  • Old applications or service accounts configured for RC4 only.

What attackers do that produces it

  • Kerberoasting — one account requesting RC4 (0x17) tickets for many user-account SPNs within minutes (Rubeus, Impacket GetUserSPNs).
  • Targeted Kerberoasting of a single high-value service account, which only stands out through RC4 use or an unusual requesting host.
  • Silver tickets do not produce 4769 at all — a service logon (4624 on the server) with no matching 4769 on any DC is a lead.

Investigation tips

  • Filter ServiceName not ending in $ and not krbtgt, then count distinct ServiceName per TargetUserName and IpAddress per hour.
  • Flag TicketEncryptionType 0x17 where the account supports AES.
  • Check whether the requesting account usually uses those services at all.
  • Pivot to the service accounts involved; if Kerberoasting is confirmed, rotate their passwords and review later logons (4624) by them.

MITRE ATT&CK techniques

TechniqueTactics
T1558.003 Steal or Forge Kerberos Tickets: KerberoastingCredential Access
T1558.002 Steal or Forge Kerberos Tickets: Silver TicketCredential Access

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

3 SigmaHQ detection rules (release r2026-07-01) target this event.

  • High · 1
  • Medium · 2

Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

In-depth guideEvent ID 4769: Kerberos service tickets and kerberoasting

Sources and further reading