Skip to main content
AD Academy
Attacks on AD
Intermediate16 minLast updated: Topic 1 of 7

Kerberoasting

An attack on SPN accounts with weak passwords.

Not read

What you will learn here

  • How an attacker gets a service account ticket
  • Why a weak password is the real problem
  • How to detect and prevent it

is an attack in which an attacker requests tickets for Service Accounts, then tries to crack their Hash offline. If the password is weak — the attack succeeds.

משתמש רגיל עם גישה בסיסית מבצע Kerberoasting ופורץ סיסמה של חשבון שירות. משם הסלמת הרשאות עד Domain Admin, ולבסוף DCSync לחילוץ ה־hash של krbtgt ויצירת Golden Ticket לשליטה מתמשכת.

Why it works

  • Service accounts often have complex passwords that are almost never changed.
  • The ticket contains the Hash of the service account's password.
  • Any authenticated user can request a ticket for many SPNs.
Architecture and Theory — Under the Hood

A ticket is encrypted with a key derived from the service account's password. Any authenticated user can request a ticket for any — therefore, it's possible to take the ticket home and try passwords offline, without any failed login attempts.

  • RC4 (etype 23) — Broken quickly, the hash is the of the password.
  • AES (etype 17/18) — Much slower to break, so it should be enforced.
  • Only accounts with relevant SPNs; computer accounts are not interesting (random 120-character password).
Practical Configuration (PowerShell / GUI)
# Find all attackable accounts
Get-ADUser -Filter {ServicePrincipalName -like "*"} -Properties ServicePrincipalName,PasswordLastSet,msDS-SupportedEncryptionTypes

# Force AES only on a service account
Set-ADUser svc_sql -KerberosEncryptionType AES128,AES256

# Transition to gMSA (random password that changes automatically)
New-ADServiceAccount gmsa_sql -DNSHostName sql01.corp.com -PrincipalsAllowedToRetrieveManagedPassword "SQL-Servers"
powershell
Real-world Scenarios in the Organization
  • svc_sql with a password from 2014 and — most common in Pentests and genuinely gets cracked.
  • Service account that is also a Admin — one crack = domain takeover.
  • Gradual transition to gMSA for every supported service.
Troubleshooting and Diagnostics
  • Event 4769 with Ticket Encryption Type 0x17 (RC4) — a sign of a suspicious request.
  • Many 4769 events from the same workstation within seconds = Kerberoast scan.
  • After migrating to AES: If the service is cracked, ensure the DC and server support the same etype.
Glossary and Quick Command Line
  • — service/host:port.
  • — Service Ticket.
  • etype 23 = RC4, 17/18 = AES.
  • gMSA — Group Managed Service Account.

Check yourself

What does the Kerberoasting attack enable?

Was this page helpful?