Kerberoasting: retain the real zero-match result
Atlas home · Research path · Operational families · Anomaly models · Visual index
Maintained entry path added 1 October 2026. Results below are preserved reports dated 21 September 2026, not independent replication or new engine execution. Evidence provenance.
Hypothesis
A principal requests successful service tickets for an unusually broad set of service identifiers in a bounded window. This breadth hypothesis cannot cover every Kerberoasting execution.
Required fields and collection
Normalized table: WindowsEvents. These are adapter contracts, not vendor-native connector guarantees.
TimeGenerated:datetime,Computer:string,EvidenceId:string,EventID:int,Principal:string,SourceIP:string,LogonId:string,AccessMask:long,ObjectType:string,Properties:string,ServiceName:string,EncryptionType:string,ResultCode:string,LogonType:int,LogonProcess:string,AuthenticationPackage:string
Full normalized contracts · Collection requirements.
Existing query and model
The existing query filters successful 4769 events, deduplicates evidence, includes AES, excludes krbtgt and requires five distinct services in 15 minutes.
Read the maintained query in context · Download unchanged KQL.
Positive and benign or boundary fixtures
These rows come from the existing functional report. Expected and actual values describe selected logic behavior, not real-world accuracy.
| Existing fixture | Expected output | Reported observed output | Status |
|---|---|---|---|
kerberoast-aes-breadth | [["user",5]] | [["user",5]] | Reported pass |
kerberoast-machine-principal-not-hidden | [["computer$",5]] | [["computer$",5]] | Reported pass |
kerberoast-low-volume-known-blind-spot | [] | [] | Reported pass |
kerberoast-krbtgt-not-counted | [] | [] | Reported pass |
kerberoast-repeated-service-not-breadth | [] | [] | Reported pass |
Reported public-recording observation: one input 4769 record, zero query output rows. The recording is not repeated or modified to force a match. See the pinned recording manifest.
Original functional report · Exact fixture construction.
Safe reproduction and limits
Start with the offline reproduction README. Its standard-library checks parse fixtures and recorded data; they do not execute attack commands. An engine replay is a separate opt-in workflow and was not run in this change.
The pinned public recording has one input record and zero output rows: it is below the breadth threshold. That is a known miss, not evidence of benignness. Repeated requests for one service and low-volume activity remain outside the rule; machine principals are not automatically excluded.
The existing seeded 2688-entity-day study is synthetic. Its gate reduced FP 85→8 and TP 18→11. This is a constructed trade-off, not an enterprise benchmark. Eight reported KQL examples and 34 functional cases do not make the 54 catalog rows validated detectors. Full validation boundaries.