Week 1
Investigate Account Lockouts and Audit Kerberoasting Indicators at a Regional Bank
Client Background
First Frontier Bank is a regional bank with 1,200 employees and 22 branches across the mid-Atlantic. Single AD domain wrixbank.local with two DCs (primary + DR in geographically separate data centers).
Business Environment
Single-domain AD forest at functional level 2016. LAPS deployed for local admin password management. Branch connectivity over MPLS, with read-only DC deployments in some branches. Tier model not implemented.
Security Incident
On 2026-07-15, the SOC observed two convergent anomalies: 220 user accounts locked out across 14 branches within a 90-minute window, and DC Security Event 4771 (Kerberos pre-auth failed) spikes 8x baseline — a strong Kerberoasting indicator. The flood appears related to July Patch Tuesday, but the Kerberos anomaly is separate.
Scope
AD lockout policy, DC Security and Kerberos events (4740, 4771, 4769, 4625, 4738), service-account SPN configuration. Azure AD Connect is out of scope.
Objectives
- Triage the account lockout cascade and isolate root cause (mobile device, service account, or malicious spray)
- Audit DC Kerberos events (4769, 4771) for RC4-HMAC service-ticket activity and Kerberoasting indicators
- Recommend lockout-policy revision, AES-only service-account migration, and Tier-0 FGPP for privileged accounts
- Prioritize Group Managed Service Accounts (gMSAs) as the primary Kerberoasting mitigation over password-rotation cycles and lockout tuning, and detect AES-encrypted service-ticket requests.
Required Deliverables