Kerberoasting is an attack technique against Kerberos service accounts in Active Directory. A normal authenticated domain user can request a service ticket for a Service Principal Name (SPN). Part of that ticket is protected by a key derived from the service account password, allowing offline password guessing.
Why is it dangerous?
Ticket requests are expected Kerberos behavior and usually need no elevated rights. Guessing happens offline, beyond login rate limits and lockouts. A weak, old and privileged service account password can lead to privilege escalation and lateral movement.
Simplified sequence
- The attacker controls a normal domain account.
- They enumerate accounts with SPNs and their privileges.
- They request normal TGS tickets for selected services.
- Ticket material is checked against candidates offline.
- A recovered password grants the service account's rights.
Prevention
- - Prefer group Managed Service Accounts (gMSA) with long automatically rotated passwords.
- - Use long random passwords and managed rotation for unavoidable classic accounts.
- - Minimize privileges, deny interactive login and avoid Domain Admin membership.
- - Reduce legacy RC4 and configure AES; strong passwords remain necessary.
- - Regularly inventory SPNs, age, delegation and effective privileges.
Detection
Windows event 4769 records TGS requests. Signals include many SPNs in a short interval, RC4 in an AES-capable environment, unusual source hosts and correlation with directory enumeration. Individual tickets are normal, so detection needs a baseline and account/device/service context.
Useful open-source tools
Impacket supports authorized SPN and ticket testing. BloodHound visualizes privilege and service-account paths. Defenders can apply Sigma rules to 4769 events. These tools expose sensitive domain data and belong only in scoped assessments and protected analysis environments.
Thank you for your feedback! We will review it and optimize this content.
Do you have feedback on Kerberoasting? Tell us!
Additional Services
Comprehensive IT security solutions for complete protection
Red Teaming
Simulation of real attacks on your company including people, infrastructure and processes. A comprehensive approach to testing your entire security strategy.
Learn morePhishing Exercises
Practical phishing simulations to raise employee awareness. Increase awareness and reduce the risk of successful email-based attacks.
Learn more