is an attack in which an attacker requests tickets for Service Accounts, then tries to crack their Hash offline. If the password is weak — the attack succeeds.
משתמש רגיל עם גישה בסיסית מבצע Kerberoasting ופורץ סיסמה של חשבון שירות. משם הסלמת הרשאות עד Domain Admin, ולבסוף DCSync לחילוץ ה־hash של krbtgt ויצירת Golden Ticket לשליטה מתמשכת.
Why it works
- Service accounts often have complex passwords that are almost never changed.
- The ticket contains the Hash of the service account's password.
- Any authenticated user can request a ticket for many SPNs.