Case A0C5CD · Identity & AD · L3 Applied
Kerberoasting
Practise as: Explain it · Interview · Deep dive
Interview questionWhat is Kerberoasting and how would you both detect and prevent it?
- 01 What is it?
- 02 How is it abused?
- 03 How do you stop it?
What a strong answer covers
Try it out loud first. Then check yourself:
- Any domain user can request a TGS for any account with an SPN; part of it is encrypted with that account password hash
- Attacker cracks the ticket offline (hashcat mode 13100 for RC4) to recover the service account password
- Detect: 4769 events with ticket encryption type 0x17 (RC4) or one user requesting many SPNs in a short window
- Prevent: gMSA or 25+ char random passwords, enforce AES-only via msDS-SupportedEncryptionTypes, remove stale SPNs
- Honeypot SPN accounts with no legitimate use give high-fidelity alerts when a ticket is requested
If the interviewer pushes back
- If the org enforces AES, is Kerberoasting dead? What changes for the attacker and for detection?
- How does targeted Kerberoasting work when you have GenericWrite on a user without an SPN?
Go deeper
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.