7.4 - Kerberoasting
Kerberoasting
Kerberos Ticket Exchange for Services
3) TGS-REQ (Client -> KDC/TGS)
- TGT 🔑 Encrypted with KDC key
- Authenticator Data 🔑 Encrypted with TGS Session Key
4) TGS-REP (KDC/TGS -> Client)
- ST 🔑 Encrypted with Service key
- Service Session Key 🔑 Encrypted with TGS Session KeyExample: Exploiting Kerberoasting
New-ADUser -Name "kerberoasting" -SamAccountName "kerberoasting" -UserPrincipalName "kerberoasting@dev-angelist" -AccountPassword (ConvertTo-SecureString -AsPlainText "Password123!" -Force) -Enabled $trueSet-ADUser -Identity "kerberoasting" -ServicePrincipalNames @{Add="HTTP/kerberoasting.dev-angelist.lab"}




Troubleshooting: Clock Skew Errors
Other Resources
Labs
Last updated