Kerberoasting
Read first: AD privileges & permissions
TL;DR
Kerberoasting abuses a normal Kerberos feature: any domain user can request a service ticket for an account that runs a service, and part of that ticket is encrypted with the service account’s password hash — so it can be cracked offline. The defence is strong service-account passwords (or gMSAs) and AES.
What it is
Service accounts in Active Directory are identified by a Service Principal Name (SPN). Kerberos lets any authenticated user ask for a ticket to a service, and the ticket is encrypted with the service account’s key. That’s by design — the weakness is weak service-account passwords.
How it works
An attacker with any domain foothold requests tickets for accounts that have SPNs, takes them away, and cracks them offline. No elevated rights are needed to ask, which is what makes it so common. Weak or old passwords (and legacy RC4 tickets) fall quickly.
How to detect it
- Anomalous service-ticket requests (Event ID 4769), especially a single account requesting many, or RC4 requests where AES is expected.
How to defend
- Long, random service-account passwords, or better, Group Managed Service Accounts (gMSA) that rotate automatically.
- Enforce AES, and audit which accounts even need an SPN.
Reference: MITRE ATT&CK T1558.003.