Skip to content

Kerberoasting

Kerberoasting is a technique that exploits the Kerberos protocol to extract NTLM hashes from service account credentials, enabling attackers to attempt password recovery. This attack targets service principal names (SPNs) configured for services like SQL Server, IIS, or LDAP, which often have weak or default passwords. By leveraging the Kerberos authentication process, an attacker can request a Ticket Granting Service (TGS) ticket for a service account and then extract the encrypted hash, which can be cracked offline.


Attack Process Overview

  1. Target Identification:
    The attacker identifies service accounts with SPNs that are accessible to the attacker’s domain credentials. These accounts are often misconfigured or use default passwords.

  2. AS-REQ Request:
    The attacker sends an Authentication Request (AS-REQ) to the Key Distribution Center (KDC) to obtain a Ticket Granting Ticket (TGT). This step typically requires valid domain credentials (e.g., via mimikatz or Rubeus).

  3. TGS Ticket Request:
    Using the TGT, the attacker requests a Ticket Granting Service (TGS) ticket for a specific SPN (e.g., SQLSvc/SQLServer). The TGS ticket is encrypted with the service account’s password hash.

  4. Hash Extraction:
    The attacker saves the TGS ticket (e.g., SQLSvc_SQLServer.kirbi) and uses tools like hashcat or John the Ripper to crack the encrypted hash. Since the ticket is encrypted with the service account’s password, successful cracking grants access to the service.


Tools and Commands

1. CrackMapExec (CME)

crackmapexec kerberos <target_ip> -u <username> -p <password> --spns
This command requests TGS tickets for all SPNs associated with the target domain. The output includes the encrypted hash.

2. Impacket's kerberoast Module

from impacket.krb5 import kerberosv5
from impacket.krb5.asn1 import TGSRep

# Example: Request TGS ticket for a specific SPN
realm = 'EXAMPLE.COM'
spn = 'HTTP/localhost'
tgt = ...  # Pre-obtained TGT
context = kerberosv5.Kerberos5Context()
ccache = kerberosv5.CCache()
ccache.addTicket(tgt)
tgs, cipher, _ = context.getTGS(spn, realm, ccache)
The tgs object contains the encrypted hash, which can be exported for offline cracking.

3. Mimikatz (Windows)

mimikatz # kerberos::list /spn
mimikatz # kerberos::ticket /export
Mimikatz can enumerate SPNs and export TGS tickets for further analysis.


Mitigations and Considerations

  • Strong Passwords: Service accounts should use complex, unique passwords.
  • Disable Unnecessary SPNs: Minimize the number of SPNs configured to reduce attack surface.
  • Kerberos Pre-Authentication: Enabling Kerberos pre-authentication (via msDS-UserAccountControl) prevents attackers from requesting TGS tickets without proving their password.
  • Monitoring: Regularly audit Kerberos ticket requests and detect anomalous SPN usage.

Key takeaways

  • Kerberoasting exploits weak service account passwords by extracting NTLM hashes from TGS tickets.
  • Attackers use tools like CrackMapExec or Impacket to request and crack these hashes.
  • Mitigations include enforcing strong passwords, disabling unused SPNs, and enabling Kerberos pre-authentication.
  • The attack highlights the importance of securing service accounts and monitoring Kerberos activity.