← Event ID reference
4769

A Kerberos service ticket was requested

  • Log: Security
  • Source: Microsoft-Windows-Security-Auditing
  • Kerberos & NTLM
  • Info

What it means

A user requested access to a service (a file server, SQL, a web app) through Kerberos.

Why it matters

Large numbers of RC4 (0x17) ticket requests for service accounts are a sign of Kerberoasting.

What to do

  • Alert on many 4769s with Ticket Encryption Type 0x17 from one account.
  • Give service accounts long passwords or use gMSAs.

Find it with PowerShell

Get-WinEvent -MaxEvents 20 -FilterHashtable @{
  LogName = 'Security'; Id = 4769
} | Select-Object TimeCreated, ProviderName, Message

Add -ComputerName SERVER to query another machine. Other event sources can reuse the same ID number, so check the ProviderName column.

Source

Seeing a lot of these? We can investigate, or alert you automatically through our monitoring.

Talk to us