Kerberoasting and Its Modern Variants: Why Classic Detection Still Misses Half the Attacks
Classic Kerberoasting detection looks for RC4 TGS requests. Attackers switched to AES years ago. Targeted Kerberoasting, roasting with machine accounts, and AS-REP roasting all have different signatures. This covers all variants and how to hunt each one.