014,121 GitHub stars
02Provides pre-built detection logic for Splunk and Microsoft Sentinel (KQL)
03Analyzes Kerberos TGT/TGS anomalies via Event IDs 4768 and 4769
04Detects RC4 (0x17) encryption downgrades in AES-enforced domains
05Identifies impossible ticket lifetimes exceeding default domain policies
06Correlates service ticket requests appearing without prior authentication logs