// REFERENCE
4768 — Kerberos TGT requested (AS-REQ)
Log: Security
Medium risk
A client requested a TGT from the domain controller (initial authentication). It's the basis to profile authentication activity; weak encryption types (RC4) in the ticket can betray Kerberos attacks. Logged on the DC.
Related tools
Work with this in:
Related
4769
4769 — Kerberos service ticket requested (TGS-REQ) 4770
4770 — Kerberos service ticket renewed 4771
4771 — Kerberos pre-authentication failed 4776
4776 — NTLM credential validation
4769 — Kerberos service ticket requested (TGS-REQ) 4770
4770 — Kerberos service ticket renewed 4771
4771 — Kerberos pre-authentication failed 4776
4776 — NTLM credential validation
Original descriptions based on Microsoft's public documentation. IDs and fields may vary with the Windows version and the active audit policy.