Forefront IT Security Services
BlogDetection
Detection

Detecting Kerberoasting: From Attack to Alert

December 2025Forefront IT Security Services2 min read

A complete walkthrough of the Kerberoasting attack chain, the artifacts it creates, and the detections your SOC needs.

Why Kerberoasting is Dangerous Requires no special privileges, generates minimal network traffic, and cracking happens offline where defenders can't see it. Any authenticated domain user can execute this attack.

What is Kerberoasting?

Kerberoasting exploits how Kerberos authentication works in Active Directory. Any authenticated domain user can request a service ticket (TGS) for any service account with a Service Principal Name (SPN). The ticket is encrypted with the service account's password hash, and attackers can crack it offline.

The Attack Chain

1. Enumerate SPNs

Attackers identify service accounts with SPNs

Rubeus.exe kerberoast /stats

2. Request Service Tickets

For each target SPN, request a TGS

Rubeus.exe kerberoast /user:svc_sql /format:hashcat

3. Offline Cracking

Crack the extracted ticket hash

hashcat -m 13100 hashes.txt wordlist.txt

If the service account has a weak password, it cracks quickly. We've seen production service accounts with passwords like Summer2024! crack in under a minute.

Detection is critical, Kerberoasting happens within legitimate Kerberos traffic.

Detection: Event IDs

Event IDDescriptionKey Fields
4769TGS Request (Primary Detection)Service Name, Client Address, Encryption Type
4768TGT Request (Context)Account Name, Source IP

Why Encryption Type Matters

Modern Kerberoasting tools specifically request RC4 encryption (0x17) because it's faster to crack than AES. If your environment uses AES by default, RC4 requests are anomalous.

Detection rule: Alert on 4769 where Encryption Type = 0x17 AND service account is sensitive

Splunk Detection Queries

Basic Kerberoasting Detection

index=windows EventCode=4769 Ticket_Encryption_Type=0x17
| stats count by Account_Name, Service_Name, Client_Address
| where count > 5

RC4 Anomaly Detection

index=windows EventCode=4769
| eval enc_type=case(
    Ticket_Encryption_Type="0x17", "RC4",
    Ticket_Encryption_Type="0x12", "AES256",
    true(), "Other")
| stats count by enc_type, Service_Name
| where enc_type="RC4"

Service Account Enumeration

index=windows EventCode=4769
| bin _time span=5m
| stats dc(Service_Name) as unique_services by Client_Address, _time
| where unique_services > 10

Prevention

  • Strong Passwords 25+ characters, randomly generated. Cracking becomes infeasible.
  • Managed Service Accounts (gMSA) Passwords auto-rotate, 120 characters. Kerberoasting doesn't work.
  • AES-Only Kerberos Disable RC4 where possible. Dramatically increases crack time.
  • Monitor Sensitive SPNs Know which service accounts exist and alert on TGS requests.

Purple Team Exercise

We run this as a purple team exercise regularly:

  1. Create a test service account with a known weak password
  2. Run Rubeus kerberoast from a test workstation
  3. Verify 4769 events appear in SIEM
  4. Check detection rules fire
  5. Tune thresholds based on baseline

This validates your detection capability without risking production credentials.

Test Your Detections

Purple team engagements validate whether your SOC can detect Kerberoasting and other AD attacks. We simulate the attack, verify detection, and help tune your rules.

Security Front Door

Find the right level of security for your business.

One monthly plan, one front door: penetration testing, Cyber Essentials, AI security, training and advice, from £1,500 a month. No hidden costs.

Forefront
UK Penetration Testing & Red Team Operations
Loading...