
A complete walkthrough of the Kerberoasting attack chain, the artifacts it creates, and the detections your SOC needs.
Why Kerberoasting is Dangerous Requires no special privileges, generates minimal network traffic, and cracking happens offline where defenders can't see it. Any authenticated domain user can execute this attack.
Kerberoasting exploits how Kerberos authentication works in Active Directory. Any authenticated domain user can request a service ticket (TGS) for any service account with a Service Principal Name (SPN). The ticket is encrypted with the service account's password hash, and attackers can crack it offline.
Attackers identify service accounts with SPNs
Rubeus.exe kerberoast /statsFor each target SPN, request a TGS
Rubeus.exe kerberoast /user:svc_sql /format:hashcatCrack the extracted ticket hash
hashcat -m 13100 hashes.txt wordlist.txtIf the service account has a weak password, it cracks quickly. We've seen production service accounts with passwords like Summer2024! crack in under a minute.
Detection is critical, Kerberoasting happens within legitimate Kerberos traffic.
| Event ID | Description | Key Fields |
|---|---|---|
| 4769 | TGS Request (Primary Detection) | Service Name, Client Address, Encryption Type |
| 4768 | TGT Request (Context) | Account Name, Source IP |
Modern Kerberoasting tools specifically request RC4 encryption (0x17) because it's faster to crack than AES. If your environment uses AES by default, RC4 requests are anomalous.
Detection rule: Alert on 4769 where Encryption Type = 0x17 AND service account is sensitiveindex=windows EventCode=4769 Ticket_Encryption_Type=0x17
| stats count by Account_Name, Service_Name, Client_Address
| where count > 5index=windows EventCode=4769
| eval enc_type=case(
Ticket_Encryption_Type="0x17", "RC4",
Ticket_Encryption_Type="0x12", "AES256",
true(), "Other")
| stats count by enc_type, Service_Name
| where enc_type="RC4"index=windows EventCode=4769
| bin _time span=5m
| stats dc(Service_Name) as unique_services by Client_Address, _time
| where unique_services > 10We run this as a purple team exercise regularly:
This validates your detection capability without risking production credentials.
Purple team engagements validate whether your SOC can detect Kerberoasting and other AD attacks. We simulate the attack, verify detection, and help tune your rules.
One monthly plan, one front door: penetration testing, Cyber Essentials, AI security, training and advice, from £1,500 a month. No hidden costs.