Kerberoasting is an attack targeting service accounts within Active Directory by exploiting Service Principal Names (SPNs). In this attack, an adversary requests Kerberos service tickets, extracts the encrypted credential data, and then attempts to crack the ticket offline to recover the plaintext password.

image.png

MITRE ATT&CK ID: T1558.003


1- How Kerberoasting Works

a. Service Ticket Request

b. Ticket Retrieval and Offline Cracking


2- Attack Impact