This lab demonstrates how Kerberoasting-style activity can be detected and investigated in an Active Directory environment using Wazuh SIEM, Windows Security logs, PowerShell logging, and process ...