Open cardosec

Case A0C5CD · Identity & AD · L3 Applied

Kerberoasting

Practise as: Explain it · Interview · Deep dive

Interview questionWhat is Kerberoasting and how would you both detect and prevent it?

  1. 01 What is it?
  2. 02 How is it abused?
  3. 03 How do you stop it?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. Any domain user can request a TGS for any account with an SPN; part of it is encrypted with that account password hash
  2. Attacker cracks the ticket offline (hashcat mode 13100 for RC4) to recover the service account password
  3. Detect: 4769 events with ticket encryption type 0x17 (RC4) or one user requesting many SPNs in a short window
  4. Prevent: gMSA or 25+ char random passwords, enforce AES-only via msDS-SupportedEncryptionTypes, remove stale SPNs
  5. Honeypot SPN accounts with no legitimate use give high-fidelity alerts when a ticket is requested

If the interviewer pushes back

  • If the org enforces AES, is Kerberoasting dead? What changes for the attacker and for detection?
  • How does targeted Kerberoasting work when you have GenericWrite on a user without an SPN?

Go deeper

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.