Score:0

KTBTGT request failure on disabled administrator

nl flag

The default domain administrator account is disabled (we have disabled it!) but I receive the following err frequently on Dcs:

Event Code:  16
User Name:   administrator
Failure Code: 0x12
Logon Service:  krbtgt/X.COM
Logon Time: Aug 12,2023 09:26:22 AM
SID: -
Remarks: A Kerberos authentication ticket (TGT) was requested.
Event Number: 4768
Domain Controller: dc1.X.com
Event Type: Failure
Client IP Address: 172.24.77.12
Domain: X.com
Failure Type: Account disabled, expired, or locked out
Client Host Name: 172.24.77.12
Record number: 486047160

I can't find why I am receiving Kerberos ticket request via disabled administrator account and how can I mitigate it.

cn flag
There are many possible reasons why a process on the endpoint that was not checked may use the name "administrator". Perhaps the hostname/authority was omitted and the domain was assumed. There is no information presented that would be useful for identifying the source.
us flag
Suggest re-naming the disabled account so the erroneous 'administrator' logins won't trigger that alert. A lot of things, especially network scanners, may attempt to try this well known username.
Score:0
cn flag

Probably, a service which running or installed with domain administrator has caused it. There are two tools what I know to analyze the situations like this.

LockoutStatus.exe: You can see login requests along with when and how many.
https://www.microsoft.com/en-US/download/details.aspx?id=15201

Aloinfo.exe: You can see which application or service uses domain administrator. https://www.microsoft.com/en-US/download/details.aspx?id=18465

Butane Sh avatar
nl flag
Thank U, I'll check the tools. but this error occurs only from one citrix VD, no service/ application is running with administrator account. notice that this is not a normal logon failure. It is related to Kerberos authentication ticket (TGT) request with administrator account.
cn flag
@ButaneSh: any process of any user can request a TGT for any account. Requesting a TGT is not significant or meaningful. It only means the request was made. https://security.stackexchange.com/questions/261002/tgs-ticket-in-kerberoasting/261060#261060
I sit in a Tesla and translated this thread with Ai:

mangohost

Post an answer

Most people don’t grasp that asking a lot of questions unlocks learning and improves interpersonal bonding. In Alison’s studies, for example, though people could accurately recall how many questions had been asked in their conversations, they didn’t intuit the link between questions and liking. Across four studies, in which participants were engaged in conversations themselves or read transcripts of others’ conversations, people tended not to realize that question asking would influence—or had influenced—the level of amity between the conversationalists.