Skip to content
Security

Event ID 4770: Kerberos service ticket renewed

A Kerberos service ticket was renewedEvent 4770 is logged on domain controllers when a client renews an existing Kerberos service ticket instead of requesting a new one.
4770
Event ID
4770
Channel
Security
Provider
Microsoft-Windows-Security-Auditing
Log file
Security.evtx
Category
Kerberos
Default logging
Logged by default

What event 4770 means

Event 4770 is written by the KDC on a domain controller when a client presents a renewable service ticket and asks for its lifetime to be extended. It is far less frequent than 4769 and mostly reflects long-running sessions and services.

On its own it rarely matters for an investigation, but it extends the timeline of an account's Kerberos activity: a renewal shows the account and client IP were still active at that time, even when no new 4769 was logged.

When it is logged

Audit policy / configuration

Advanced Audit Policy Configuration > Account Logon > Audit Kerberos Service Ticket Operations (Success). Only meaningful on domain controllers.

Key fields

FieldWhat it tells you
TargetUserNameAccount that renewed the ticket.
TargetDomainNameDomain of that account.
ServiceNameService account the ticket is for.
ServiceSidSID of the service account.
TicketOptionsTicket options (hex).
TicketEncryptionTypeEncryption type of the ticket (0x12 AES256, 0x17 RC4…); see 4769.
IpAddressClient IP address.
IpPortClient source port.

Common benign sources

  • Long-running sessions and services renewing tickets before they expire.

What attackers do that produces it

  • Little direct attacker signal; it shows continued use of a session that was established earlier, including one started with stolen credentials.

Investigation tips

  • Use it to extend the activity window of an account and IP identified from 4768/4769.
  • Tickets renewed far beyond the domain's maximum renewal lifetime are abnormal and worth checking against forged-ticket scenarios.

Sigma rules for this event

No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading