Kerberoasting

intermediateInternal & Active Directory

Read first: AD privileges & permissions

TL;DR

Kerberoasting abuses a normal Kerberos feature: any domain user can request a service ticket for an account that runs a service, and part of that ticket is encrypted with the service account’s password hash — so it can be cracked offline. The defence is strong service-account passwords (or gMSAs) and AES.

What it is

Service accounts in Active Directory are identified by a Service Principal Name (SPN). Kerberos lets any authenticated user ask for a ticket to a service, and the ticket is encrypted with the service account’s key. That’s by design — the weakness is weak service-account passwords.

How it works

An attacker with any domain foothold requests tickets for accounts that have SPNs, takes them away, and cracks them offline. No elevated rights are needed to ask, which is what makes it so common. Weak or old passwords (and legacy RC4 tickets) fall quickly.

How to detect it

How to defend

Reference: MITRE ATT&CK T1558.003.

← Back to Internal & Active Directory