What is Kerberos?
Kerberos is an authentication protocol used in Active Directory environments.
Common security issues
Kerberoasting (ticket cracking).
AS-REP roasting.
Weak service account passwords.
Ticket reuse attacks.
Default ports
88
Enumeration
Valid users, SPNs, AS-REP targets, realm and KDC discovery guides
Kerberos realm and KDC discovery
Kerberos SPN enumeration
Enumerate Service Principal Names (SPNs) via Kerberos to identify service accounts, enabling targeted Kerberoasting attacks against AD environments.
Kerberos Valid User Enumeration
Vulnerability Discovery
Find AS-REP roastable and Kerberoastable accounts via key tools
Kerberoastable Service Accounts
Identify service accounts with SPNs vulnerable to Kerberoasting by extracting and cracking TGS tickets offline to compromise Active Directory credentials.
Kerberos Pre-Authentication Not Required
Identifies accounts with DONT_REQUIRE_PREAUTH set, enabling AS-REP roasting attacks to capture and offline-crack Kerberos hashes without credentials.
Exploitation
Kerberos attacks: roasting, ticket forging, and delegation abuse
AS-REP Roasting – Pre-Auth Disabled Hash Cracking
Exploit accounts with Kerberos pre-authentication disabled to capture AS-REP hashes offline, then crack them to recover plaintext credentials.
Kerberoasting – TGS Hash Extraction and Cracking
Lateral Movement
Reuse ccache files and keytabs on Linux to move laterally in AD
Kerberos Ticket Reuse from Linux
Exploiting cached Kerberos tickets on Linux via ccache files and keytabs to authenticate as other users and move laterally across AD environments.