CRTPCAPEkerberosactive-directorySPN
Kerberoasting
Overview
TGS-REP
(encrypted with the already known User-KDC session key)
+--------------------------------------------------------+
| +----------------------------------------------------+ |
| | 1. User-Service session key | |
| | (Same session key as in the TGS) | |
| +----------------------------------------------------+ |
| |
| +----------------------------------------------------+ |
| | 2. Service Ticket (TGS) | |
| | +-------------------------------------------+ | |
| | | User information | | |
| | | + | | | -------> Kerberoast
| | | User / Service session key | | |
| | +-------------------------------------------+ | |
| | Encrypted with the service account's secret | |
+ +----------------------------------------------------+ |Service vs User Accounts
AES vs RC4 Encryption
Tools
Windows
Linux
Targeted Kerberoast
Windows
Linux
Last updated