Kerberoasting
Last updated
Last updated
Kerberoasting is an attack technique that allows attackers to target service accounts in Active Directory. These service accounts typically have SPNs (Service Principal Names) associated with them.
The attacker is able to request the Service Ticket from the Ticket Granting Server which is encrypted using the SPN's password hash.
The attack is made in few steps:
The attacker sends request to the Ticket Granting Server.
The attacker gets the Service Ticket in the request
Attacker brute-forces the Service Ticket offline to obtain the user's password.