spn-jackingactive-directoryDACLtargeted kerberoastCAPE

WriteSPN

The WriteSPN permission is technically a Write permission on the servicePrincipalName attribute. It allows a user to add, remove, or modify any SPN value without restrictions.

This can be leveraged for Targeted Kerberoast or SPN Jacking.

Last updated