Kerberoasting

๐Ÿ”’ Secure Bits ๐Ÿ’ก
๐——๐—ผ ๐˜†๐—ผ๐˜‚ ๐—ธ๐—ป๐—ผ๐˜„ ๐—ต๐—ผ๐˜„ ๐—ž๐—ฒ๐—ฟ๐—ฏ๐—ฒ๐—ฟ๐—ผ๐—ฎ๐˜€๐˜๐—ถ๐—ป๐—ด ๐˜„๐—ผ๐—ฟ๐—ธ๐˜€?

If you manage Active Directory, you absolutely should โ€” because ๐—ฎ๐—ป๐˜† ๐—ฑ๐—ผ๐—บ๐—ฎ๐—ถ๐—ป ๐˜‚๐˜€๐—ฒ๐—ฟ ๐—ฐ๐—ฎ๐—ป ๐—ฝ๐—ฒ๐—ฟ๐—ณ๐—ผ๐—ฟ๐—บ ๐—ถ๐˜.

As the name implies, the attack targets the ๐—ž๐—ฒ๐—ฟ๐—ฏ๐—ฒ๐—ฟ๐—ผ๐˜€ย authentication protocol.

Whenever an account has a ๐—ฆ๐—ฒ๐—ฟ๐˜ƒ๐—ถ๐—ฐ๐—ฒ ๐—ฃ๐—ฟ๐—ถ๐—ป๐—ฐ๐—ถ๐—ฝ๐—ฎ๐—น ๐—ก๐—ฎ๐—บ๐—ฒ (๐—ฆ๐—ฃ๐—ก) (like HOST/SERVER01), you can request a ๐—ง๐—š๐—ฆย ticket for it. This ticket is partially ๐—ฒ๐—ป๐—ฐ๐—ฟ๐˜†๐—ฝ๐˜๐—ฒ๐—ฑ ๐˜‚๐˜€๐—ถ๐—ป๐—ด ๐˜๐—ต๐—ฒ ๐—ฝ๐—ฎ๐˜€๐˜€๐˜„๐—ผ๐—ฟ๐—ฑ of the account tied to that SPN.

That TGS ticket you just requested?
โžก๏ธย Youโ€™re now holding a blob of data thatโ€™s ๐—ฒ๐—ป๐—ฐ๐—ฟ๐˜†๐—ฝ๐˜๐—ฒ๐—ฑ ๐˜„๐—ถ๐˜๐—ต ๐˜€๐—ผ๐—บ๐—ฒ๐—ผ๐—ป๐—ฒ ๐—ฒ๐—น๐˜€๐—ฒโ€™๐˜€ ๐—ฝ๐—ฎ๐˜€๐˜€๐˜„๐—ผ๐—ฟ๐—ฑ (key derived from the password). If that password is weak, you can start brute-forcing it offline. Thatโ€™s ๐—ž๐—ฒ๐—ฟ๐—ฏ๐—ฒ๐—ฟ๐—ผ๐—ฎ๐˜€๐˜๐—ถ๐—ป๐—ด.

And in many environments?
Itโ€™s a 10-year-old service account, still active, part of Domain Admins, with a weak password.
๐Ÿ“‰ Thatโ€™s a ๐—ฑ๐—ถ๐—ฟ๐—ฒ๐—ฐ๐˜ ๐—ฝ๐—ฟ๐—ถ๐˜ƒ๐—ถ๐—น๐—ฒ๐—ด๐—ฒ ๐—ฒ๐˜€๐—ฐ๐—ฎ๐—น๐—ฎ๐˜๐—ถ๐—ผ๐—ป path from standard user to full domain control.

๐—ช๐—ต๐—ฎ๐˜ ๐—ฐ๐—ฎ๐—ป ๐˜†๐—ผ๐˜‚ ๐—ฑ๐—ผ?
โœ… Use MSA/gMSA/DMSA wherever possible.
โœ… Avoid standard user accounts for services.

If you really need to use a standard user account (it happens, I know):
โœ… Apply Fine-Grained Password Policies โ€” for example, in the Czech Republic, the law requires technical accounts to have complex 22+ character passwords.
โœ…Authentication Policies – I will explain these in the future ๐Ÿ™‚

Want to dive deeper into Kerberos ?
I cover it in my ๐—ž๐—ฒ๐—ฟ๐—ฏ๐—ฒ๐—ฟ๐—ผ๐˜€ ๐—ฐ๐—ผ๐˜‚๐—ฟ๐˜€๐—ฒ, ๐˜„๐—ต๐—ถ๐—ฐ๐—ต ๐—ถ๐˜€ ๐Ÿญ๐Ÿฌ๐Ÿฌ% ๐—ณ๐—ฟ๐—ฒ๐—ฒ and part of my Academy.

๐Ÿ‘‰ How do you secure your service accounts? Are you aware of all of them?