Sub-technique of T1558 Steal or Forge Kerberos Tickets.View on attack.mitre.org
Adversaries may abuse a valid Kerberos ticket-granting ticket (TGT) or sniff network traffic to obtain a ticket-granting service (TGS) ticket that may be vulnerable to Brute Force.
Service principal names (SPNs) are used to uniquely identify each instance of a Windows service. To enable authentication, Kerberos requires that SPNs be associated with at least one service logon account (an account specifically tasked with running a service).
Adversaries possessing a valid Kerberos ticket-granting ticket (TGT) may request one or more Kerberos ticket-granting service (TGS) service tickets for any SPN from a domain controller (DC). Portions of these tickets may be encrypted with the RC4 algorithm, meaning the Kerberos 5 TGS-REP etype 23 hash of the service account associated with the SPN is used as the private key and is thus vulnerable to offline Brute Force attacks that may expose plaintext credentials.
This same behavior could be executed using service tickets captured from network traffic.
Cracked hashes may enable Persistence, Privilege Escalation, and Lateral Movement via access to Valid Accounts.
Rules on DetectionCode tagged with T1558.003.
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Kerberoasting spn request with RC4 encryption | TTP | NULL | Windows Event Log Security 4769 |
| Rubeus Command Line Parameters | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| ServicePrincipalNames Discovery with PowerShell | TTP | NULL | Powershell Script Block Logging 4104 |
| ServicePrincipalNames Discovery with SetSPN | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Unusual Number of Kerberos Service Tickets Requested | Anomaly | NULL | Windows Event Log Security 4769 |
| Windows PowerView Kerberos Service Ticket Request | TTP | NULL | Powershell Script Block Logging 4104 |
| Windows PowerView SPN Discovery | TTP | NULL | Powershell Script Block Logging 4104 |
| Windows Process With NetExec Command Line Parameters | TTP | NULL | Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2 |
| Used by | Procedure example |
|---|---|
| GroupFIN7 | FIN7 has used Kerberoasting PowerShell commands such as, `Invoke-Kerberoast` for credential access and to enable lateral movement. |
| GroupIndrik Spider | Indrik Spider has conducted Kerberoasting attacks using a module from GitHub. |
| GroupWizard Spider | Wizard Spider has used Rubeus, MimiKatz Kerberos module, and the Invoke-Kerberoast cmdlet to steal AES hashes. |
| Used by | Procedure example |
|---|---|
| ToolBrute Ratel C4 | Brute Ratel C4 can decode Kerberos 5 tickets and convert it to hashcat format for subsequent cracking. |
| ToolEmpire | Empire uses PowerSploit's |
| ToolImpacket | Impacket modules like GetUserSPNs can be used to get Service Principal Names (SPNs) for user accounts. The output is formatted to be compatible with cracking tools like John the Ripper and Hashcat. |
| ToolPowerSploit | PowerSploit's |
| ToolRubeus | Rubeus can use the `KerberosRequestorSecurityToken.GetRequest` method to request kerberoastable service tickets. |
| ToolSILENTTRINITY | SILENTTRINITY contains a module to conduct Kerberoasting. |
| Used by | Procedure example |
|---|---|
| CampaignLeviathan Australian Intrusions | Leviathan used Kerberoasting techniques during Leviathan Australian Intrusions. |
| CampaignOperation Wocao | During Operation Wocao, threat actors used PowerSploit's `Invoke-Kerberoast` module to request encrypted service tickets and bruteforce the passwords of Windows service accounts offline. |
| CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 obtained Ticket Granting Service (TGS) tickets for Active Directory Service Principle Names to crack offline. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.