Skip to main content
Kerberoasting is one of the most effective post-compromise attacks for escalating privileges in Active Directory environments by targeting service accounts with weak passwords.

Overview

Kerberoasting attacks request service tickets for accounts with Service Principal Names (SPNs) and extract the ticket’s encrypted portion for offline password cracking. This technique exploits the fact that service tickets are encrypted with the target service account’s password hash.

Service Discovery

Identify accounts with Service Principal Names

Ticket Extraction

Request and extract encrypted service tickets

Offline Cracking

Crack extracted hashes with external tools
Kerberoasting Attack Flow

Attack Methodology

1

SPN Discovery

Identify service accounts in the domain with registered SPNs
2

Ticket Request

Request TGS tickets for target service accounts
3

Hash Extraction

Extract encrypted portion of service tickets
4

Offline Cracking

Use hashcat or John to crack the extracted hashes
5

Credential Validation

Test cracked credentials for access and privileges

Syntax Variations

Targeting Parameters

Response Format

Target Information
object
Details about the targeted service account
Hash
string
Extracted hash in specified format for cracking
Statistics
object
Summary information about the operation

Hash Format Examples

Format Components
object
Breakdown of hashcat format structure
Cracking Command:

Complete Attack Workflow

1

Initial Reconnaissance

Discover service accounts and assess the target environment:
2

OPSEC-Safe Extraction

Perform the actual kerberoasting with stealth considerations:
3

Hash Processing

Prepare hashes for cracking with external tools:
4

Offline Cracking

Use hashcat or John the Ripper to crack the extracted hashes:
5

Credential Validation

Test cracked credentials for access and privileges:

Advanced Targeting Strategies

OPSEC Considerations

Detection Risk: Kerberoasting generates TGS requests that can be monitored by security tools and may appear in domain controller logs.

Troubleshooting

Integration with Other Tools

BloodHound Integration

Use BloodHound to identify high-value service accounts before kerberoasting

Hashcat/John

Process extracted hashes with dedicated password cracking tools

Impacket Integration

Use GetUserSPNs.py for alternative SPN enumeration and targeting

PowerView Integration

Combine with PowerView for enhanced Active Directory reconnaissance

asreproast

Alternative credential attack for accounts without pre-auth

asktgt

Use cracked credentials to request TGTs

s4u

Abuse service accounts with delegation rights

silver

Create silver tickets with compromised service accounts