Kerberoasting
Overview
Exploitation
Find Accounts with SPN
# Windows built-in
setspn -T DOMAIN -Q ​*/*
# PowerView
Get-NetUser -SPN | Select -ExpandProperty serviceprincipalname
# AD Module
Get-ADUser -Filter { ServicePrincipalName -ne "$null" } -Properties ServicePrincipalNameForce Set SPN
Extracting Tickets
Extracting Hashes
Detection
Mitigation
Last updated