Event ID 4769: Kerberos service ticket requested
- Event ID
- 4769
- Channel
- Security
- Provider
- Microsoft-Windows-Security-Auditing
- Log file
- Security.evtx
- Category
- Kerberos
- Default logging
- Logged by default
What event 4769 means
Event 4769 is written by the KDC on a domain controller when an account that already holds a TGT asks for a ticket to a specific service (a Ticket Granting Service request). Every access to a Kerberos-protected resource — file shares, SQL Server, HTTP with Windows authentication, LDAP, other hosts — produces one.
The ServiceName field shows which service account the ticket is for, and TicketEncryptionType shows how it is encrypted. That combination is how Kerberoasting is found: an attacker requests tickets for user accounts that have an SPN, preferably RC4-encrypted (0x17) because they crack faster offline. Requests like that for many services in a short time, from one account, are the classic signature.
Volume is very high on DCs. Exclude computer accounts (ServiceName ending in $) and krbtgt before hunting.
When it is logged
Advanced Audit Policy Configuration > Account Logon > Audit Kerberos Service Ticket Operations (Success, Failure). Only meaningful on domain controllers.
Check the effective policy with auditpol /get /subcategory:"Kerberos Service Ticket Operations"; Failure auditing is often not enabled.
Key fields
| Field | What it tells you | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| TargetUserName | Account that requested the service ticket, in user@DOMAIN form. | ||||||||||||
| TargetDomainName | Domain of the requesting account. | ||||||||||||
| ServiceName | Account that runs the service the ticket is for. Computer accounts end in $; a user account here means a service with an SPN on a user — a Kerberoasting target. | ||||||||||||
| ServiceSid | SID of the service account. | ||||||||||||
| TicketOptions | Kerberos ticket options requested (hex). | ||||||||||||
| TicketEncryptionType | Encryption type of the service ticket.
| ||||||||||||
| Status | Kerberos result code; 0x0 means the ticket was issued. | ||||||||||||
| IpAddress | Client IP address. | ||||||||||||
| IpPort | Client source port. | ||||||||||||
| LogonGuid | GUID linking this request to the logon (the same GUID appears in the 4624 on the target server). | ||||||||||||
| TransmittedServices | Services involved in delegation (constrained delegation / S4U), otherwise -. |
Common benign sources
- Normal access to file servers, SQL, IIS and other Kerberos services — thousands per hour on busy DCs.
- Computers requesting tickets to DCs (LDAP, CIFS) for Group Policy processing.
- Old applications or service accounts configured for RC4 only.
What attackers do that produces it
- Kerberoasting — one account requesting RC4 (
0x17) tickets for many user-account SPNs within minutes (Rubeus, Impacket GetUserSPNs). - Targeted Kerberoasting of a single high-value service account, which only stands out through RC4 use or an unusual requesting host.
- Silver tickets do not produce 4769 at all — a service logon (4624 on the server) with no matching 4769 on any DC is a lead.
Investigation tips
- Filter ServiceName not ending in
$and notkrbtgt, then count distinct ServiceName per TargetUserName and IpAddress per hour. - Flag TicketEncryptionType
0x17where the account supports AES. - Check whether the requesting account usually uses those services at all.
- Pivot to the service accounts involved; if Kerberoasting is confirmed, rotate their passwords and review later logons (4624) by them.
MITRE ATT&CK techniques
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
3 SigmaHQ detection rules (release r2026-07-01) target this event.
- High · 1
- Medium · 2
- HighKerberos ManipulationRule by Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
- MediumKerberoasting Activity - Initial QueryRule by @kostastsale, SigmaHQ, DRL 1.1
- MediumSuspicious Kerberos RC4 Ticket EncryptionRule by Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.