Advisor

Kerberoasting Attacks

2 min read
Jump to:

Overview

Kerberoasting is a post-compromise attack technique targeting service accounts in Active Directory environments. It enables adversaries to extract service ticket hashes for offline password cracking, facilitating privilege escalation and lateral movement. This technique is commonly employed after initial access to escalate privileges and gain broader domain control.

Attack Objective

  • Obtain plaintext credentials of service accounts to escalate privileges
  • Supports Privilege Escalation and Lateral Movement stages of the attack lifecycle
  • Advances attacker position by enabling access to sensitive services and accounts with elevated permissions

How the Technique Works

Kerberoasting exploits the Kerberos authentication protocol by requesting service tickets (Ticket Granting Service tickets) for service accounts registered in Active Directory. These tickets are encrypted with the service account’s NTLM hash. Adversaries extract these tickets from memory or network traffic and perform offline brute-force or dictionary attacks to recover the plaintext password, bypassing network detection and authentication controls.

Common Methods & Variations

  • Requesting service tickets via standard Kerberos protocol queries using legitimate domain user accounts
  • Targeting on-premises Active Directory environments; cloud identity systems with Kerberos support may also be susceptible
  • Utilizing built-in operating system tools and libraries (living-off-the-land) rather than custom malware to avoid detection

Indicators of Compromise (IOCs)

  • Unusual Kerberos Ticket Granting Service (TGS) requests for service accounts outside normal user behavior
  • Multiple TGS requests from a single account in a short timeframe
  • Presence of extracted service ticket hashes in memory or on disk
  • Authentication logs showing anomalous service ticket requests or failed brute-force attempts

Detection Strategies

  • Monitoring Kerberos authentication logs and Security Event Logs for abnormal TGS request patterns
  • Behavioral detection focusing on unusual volume or timing of service ticket requests
  • Correlation of account activity with known Kerberoasting patterns and brute-force attempts

Mitigation & Prevention

  • Enforce strong, complex passwords and regular rotation for service accounts
  • Limit the number of service accounts with SPNs (Service Principal Names) and restrict their privileges
  • Implement managed service accounts or group managed service accounts to reduce credential exposure
  • Apply least privilege principles and monitor service account usage

Response Considerations

  • Immediately identify and isolate compromised accounts and systems
  • Investigate the scope of ticket requests and password cracking attempts
  • Reset passwords for targeted service accounts and review associated permissions
  • Enhance monitoring and apply additional controls to prevent recurrence

Related Techniques

  • Credential Dumping – to obtain additional account credentials
  • Pass-the-Ticket – leveraging stolen Kerberos tickets for lateral movement
  • Account Manipulation – modifying service account attributes to facilitate persistence

Mapping & References

  • MITRE ATT&CK T1558.003: Kerberoasting
  • Public research articles and whitepapers on Kerberoasting detection and mitigation
  • Security advisories from identity management and Active Directory vendors
Tags: Active Directory credential theft Cybersecurity Identity Security Kerberoasting Kerberos lateral movement Post-Compromise privilege escalation TTPs