Kerberoasting detection in 2026: the 4769 signals that hold up, AES downgrade tells, and clearing service-account account noin week one
Encryption-type detancy deton Kerberos TGS requests still catches lazy roasting, but as RC4 gets disabled the durable signal moves to behavior. What to grep for, why the AES downgrade tell degrades, and how to kill service-account false positives before they bury the SOC.