Detecting Kerberos Attacks (T1558): Kerberoasting, AS-REP Roasting & Forged Tickets in KQL and SPL
Production KQL (Microsoft Sentinel) and SPL (Splunk) detections for MITRE ATT&CK T1558 — Kerberoasting, AS-REP Roasting, Golden and Silver Tickets — with Event 4769/4768 logic and tuning guidance for SOC teams.