LiveActive security incident?Get immediate response
MITRE ATT&CK® Technique

T1558.003: Kerberoasting

Adversaries may abuse a valid Kerberos ticket-granting ticket (TGT) or sniff network traffic to obtain a ticket-granting service (TGS) ticket that may be vulnerable to Brute Force.[1][2]

Service principal names (SPNs) are used to uniquely identify each instance of a Windows service. To enable authentication, Kerberos requires that SPNs be associated with at least one service logon account (an account specifically tasked with running a service[3]).[4][5][6][7]

Adversaries possessing a valid Kerberos ticket-granting ticket (TGT) may request one or more Kerberos ticket-granting service (TGS) service tickets for any SPN from a domain controller (DC).[1][2] Portions of these tickets may be encrypted with the RC4 algorithm, meaning the Kerberos 5 TGS-REP etype 23 hash of the service account associated with the SPN is used as the private key and is thus vulnerable to offline Brute Force attacks that may expose plaintext credentials.[2][1] [7]

This same behavior could be executed using service tickets captured from network traffic.[2]

Cracked hashes may enable Persistence, Privilege Escalation, and Lateral Movement via access to Valid Accounts.[6]

EnterpriseT1558.003Sub-techniqueObject v1.3Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceHigh

Kerberoasting matters because it turns normal Windows Kerberos service-ticket behavior into a credential-access path against Active Directory service accounts. If a service account password is weak enough to crack offline, the resulting valid account can support persistence, privilege escalation, and lateral movement, making this a high-value control-validation topic for Windows domain resilience.

Executive priority

Prioritize this where Windows domains depend on service principal names and long-lived service accounts. Leadership should ask whether service accounts are least-privileged, governed by strong password policy, monitored when Kerberos service tickets are requested, and included in incident-response credential rotation plans. This is also useful audit evidence: it connects privileged account management, password policy, encryption choices, and domain-controller logging to a concrete credential-access risk.

Technical view

ATT&CK lists Kerberoasting as a Windows credential-access sub-technique under Steal or Forge Kerberos Tickets. The behavior involves a valid TGT or captured network traffic being used to obtain TGS service tickets for SPNs; portions of those tickets may use RC4, exposing Kerberos 5 TGS-REP etype 23 material to offline brute force. SOC and IR teams should validate visibility at domain controllers, SPN/service-account inventory quality, and whether alerts can distinguish expected service-ticket activity from unusual requests against many SPNs or sensitive service accounts. ATT&CK provides no official detection text, but relates DET0157, Detect Kerberoasting Attempts, to this object.

Likely telemetry

  • Domain controller Kerberos authentication and TGS request logs
  • Service principal name inventory and the associated service logon accounts
  • Service account privilege, role, and password policy records
  • Network telemetry where Kerberos service tickets may be observed or captured
  • Endpoint and script/process telemetry on Windows systems where Kerberos-focused tools may run

Detection direction

  • Confirm domain controllers generate and retain Kerberos service-ticket request evidence sufficient to identify requests for SPNs and RC4/TGS-REP etype 23 patterns where available.
  • Baseline normal service-ticket request volume by user, host, service account, and SPN so detection logic can focus on unusual breadth, frequency, or access to sensitive service accounts.
  • Tune carefully for administrators, scanners, applications, and legitimate service discovery that may request many tickets and create false positives.
  • Use relationship context for validation: ATT&CK links Kerberoasting to public tools/frameworks including PowerSploit, Impacket, Empire, SILENTTRINITY, Brute Ratel C4, and Rubeus, so endpoint/script telemetry may add corroboration but should not be the only detection path.
  • Treat gaps in DC logging, SPN ownership data, and service-account privilege mapping as material blind spots because the cracking activity can occur offline after ticket material is obtained.

Mitigation priorities

  • Start with privileged account management: reduce service-account privileges, assign clear ownership, monitor use, and ensure accountability through logging and auditing.
  • Enforce strong password policies for service accounts, with length and complexity appropriate to resist offline brute force and with controls against reuse.
  • Review SPNs and remove or correct unnecessary, stale, or over-privileged service account associations.
  • Prefer strong encryption choices for sensitive authentication material where supported by the environment, consistent with the ATT&CK mitigation relationship to Encrypt Sensitive Information.
  • Include suspected Kerberoasting in IR playbooks: identify requested SPNs, assess exposed service accounts, rotate affected credentials, and review subsequent valid-account activity for persistence, privilege escalation, or lateral movement.
Additional notes and limits

This object supersedes revoked technique T1208 and is a sub-technique of T1558, Steal or Forge Kerberos Tickets. ATT&CK relationships show use by multiple campaigns/groups and availability in several public or commercial toolsets, which supports prioritizing defensive validation without implying current activity in any specific environment.

The supplied ATT&CK object has no official detection procedure, so detection guidance is derived from the technique description and relationship context. Local Windows domain configuration, Kerberos logging, encryption settings, SPN hygiene, and service-account privilege data are required to determine actual exposure and coverage.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Kerberoasting

Adversaries may abuse a valid Kerberos ticket-granting ticket (TGT) or sniff network traffic to obtain a ticket-granting service (TGS) ticket that may be vulnerable to Brute Force.[1][2]

Service principal names (SPNs) are used to uniquely identify each instance of a Windows service. To enable authentication, Kerberos requires that SPNs be associated with at least one service logon account (an account specifically tasked with running a service[3]).[4][5][6][7]

Adversaries possessing a valid Kerberos ticket-granting ticket (TGT) may request one or more Kerberos ticket-granting service (TGS) service tickets for any SPN from a domain controller (DC).[1][2] Portions of these tickets may be encrypted with the RC4 algorithm, meaning the Kerberos 5 TGS-REP etype 23 hash of the service account associated with the SPN is used as the private key and is thus vulnerable to offline Brute Force attacks that may expose plaintext credentials.[2][1] [7]

This same behavior could be executed using service tickets captured from network traffic.[2]

Cracked hashes may enable Persistence, Privilege Escalation, and Lateral Movement via access to Valid Accounts.[6]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Related techniques

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

2 rows
DomainIDNameRelationship / procedure
EnterpriseT1208KerberoastingKerberoasting revoked by this object.
EnterpriseT1558Steal or Forge Kerberos TicketsThis object subtechnique of Steal or Forge Kerberos Tickets.
Associated objects

Groups, software, and campaigns

GroupEnterprise

G0102: Wizard Spider

Wizard Spider is a Russia-based financially motivated threat group originally known for the creation and deployment of TrickBot since at least 2016. Wizard Spider possesses a diverse arsenal of tools and has conducted ransomware campaigns against a variety of organizations, ranging from major corporations to hospitals.[1][2][3]

GroupEnterprise

G0046: FIN7

FIN7 is a financially-motivated threat group that has been active since 2013. FIN7 has targeted the retail, restaurant, hospitality, software, consulting, financial services, medical equipment, cloud services, media, food and beverage, transportation, pharmaceutical, and utilities industries in the United States. A portion of FIN7 was operated out of a front company called Combi Security and often used point-of-sale malware for targeting efforts. Since 2020, FIN7 shifted operations to big game hunting (BGH), including use of REvil ransomware and their own Ransomware-as-a-Service (RaaS), Darkside. FIN7 may be linked to the Carbanak Group, but multiple threat groups have been observed using Carbanak, leading these groups to be tracked separately.[1][2][3][4][5][6][7]

ToolEnterprise

S1071: Rubeus

Rubeus is a C# toolset designed for raw Kerberos interaction that has been used since at least 2020, including in ransomware operations.[1][2][3][4]

Windows
ToolEnterprise

S0357: Impacket

Impacket is an open source collection of modules written in Python for programmatically constructing and manipulating network protocols. Impacket contains several tools for remote service execution, Kerberos manipulation, Windows credential dumping, packet sniffing, and relay attacks.[1]

LinuxmacOSWindows
ToolEnterprise

S0363: Empire

Empire is an open-source, cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python, the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries.[1][2][3]

LinuxmacOSWindows
ToolEnterprise

S0692: SILENTTRINITY

SILENTTRINITY is an open source remote administration and post-exploitation framework primarily written in Python that includes stagers written in Powershell, C, and Boo. SILENTTRINITY was used in a 2019 campaign against Croatian government agencies by unidentified cyber actors.[1][2]

Windows
ToolEnterprise

S0194: PowerSploit

PowerSploit is an open source, offensive security framework comprised of PowerShell modules and scripts that perform a wide range of tasks related to penetration testing such as code execution, persistence, bypassing anti-virus, recon, and exfiltration. [1] [2] [3]

Windows
ToolEnterprise

S1063: Brute Ratel C4

Brute Ratel C4 is a commercial red-teaming and adversarial attack simulation tool that first appeared in December 2020. Brute Ratel C4 was specifically designed to avoid detection by endpoint detection and response (EDR) and antivirus (AV) capabilities, and deploys agents called badgers to enable arbitrary command execution for lateral movement, privilege escalation, and persistence. In September 2022, a cracked version of Brute Ratel C4 was leaked in the cybercriminal underground, leading to its use by threat actors.[1][2][3][4][5]

Windows
CampaignEnterprise

C0049: Leviathan Australian Intrusions

Leviathan Australian Intrusions consisted of at least two long-term intrusions against victims in Australia by Leviathan, relying on similar tradecraft such as external service exploitation followed by extensive credential capture and re-use to enable privilege escalation and lateral movement. Leviathan Australian Intrusions were focused on exfiltrating sensitive data including valid credentials for the victim organizations.[1]

CampaignEnterprise

C0014: Operation Wocao

Operation Wocao was a cyber espionage campaign that targeted organizations around the world, including in Brazil, China, France, Germany, Italy, Mexico, Portugal, Spain, the United Kingdom, and the United States. The suspected China-based actors compromised government organizations and managed service providers, as well as aviation, construction, energy, finance, health care, insurance, offshore engineering, software development, and transportation companies.[1]

Security researchers assessed the Operation Wocao actors used similar TTPs and tools as APT20, suggesting a possible overlap. Operation Wocao was named after an observed command line entry by one of the threat actors, possibly out of frustration from losing webshell access.[1]

CampaignEnterprise

C0024: SolarWinds Compromise

The SolarWinds Compromise was a sophisticated supply chain cyber operation conducted by APT29 that was discovered in mid-December 2020. APT29 used customized malware to inject malicious code into the SolarWinds Orion software build process that was later distributed through a normal software update; they also used password spraying, token theft, API abuse, spear phishing, and other supply chain attacks to compromise user accounts and leverage their associated access. Victims of this campaign included government, consulting, technology, telecom, and other organizations in North America, Europe, Asia, and the Middle East. This activity has been labled the StellarParticle campaign in industry reporting.[1] Industry reporting also initially referred to the actors involved in this campaign as UNC2452, NOBELIUM, Dark Halo, and SolarStorm.[2][3][4][5][1][6][7][8]

In April 2021, the US and UK governments attributed the SolarWinds Compromise to Russia's Foreign Intelligence Service (SVR); public statements included citations to APT29, Cozy Bear, and The Dukes.[9][10][11] The US government assessed that of the approximately 18,000 affected public and private sector customers of Solar Winds’ Orion product, a much smaller number were compromised by follow-on APT29 activity on their systems.[12]

Relationship explorer

All related ATT&CK context

Mitigations

Mitigation direction

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.3
Created
Modified
Raw hash
abb0201242267fd3...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.11.3Current bundleabb020124226…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    Empire InvokeKerberoast Oct 2016

    EmpireProject. (2016, October 31). Invoke-Kerberoast.ps1. Retrieved March 22, 2018.

    Open source URL
  2. [2]
    AdSecurity Cracking Kerberos Dec 2015

    Metcalf, S. (2015, December 31). Cracking Kerberos TGS Tickets Using Kerberoast – Exploiting Kerberos to Compromise the Active Directory Domain. Retrieved March 22, 2018.

    Open source URL
  3. [3]
    Microsoft Detecting Kerberoasting Feb 2018

    Bani, M. (2018, February 23). Detecting Kerberoasting activity using Azure Security Center. Retrieved March 23, 2018.

    Open source URL
  4. [4]
    Microsoft SPN

    Microsoft. (n.d.). Service Principal Names. Retrieved March 22, 2018.

    Open source URL
  5. [5]
    Microsoft SetSPN

    Microsoft. (2010, April 13). Service Principal Names (SPNs) SetSPN Syntax (Setspn.exe). Retrieved March 22, 2018.

    Open source URL
  6. [6]
    SANS Attacking Kerberos Nov 2014

    Medin, T. (2014, November). Attacking Kerberos - Kicking the Guard Dog of Hades. Retrieved March 22, 2018.

    Open source URL
  7. [7]
    Harmj0y Kerberoast Nov 2016

    Schroeder, W. (2016, November 1). Kerberoasting Without Mimikatz. Retrieved September 23, 2024.

    Open source URL
  8. [8]
    GitHub Rubeus March 2023

    Harmj0y. (n.d.). Rubeus. Retrieved March 29, 2023.

    Open source URL
  9. [9]
    Impacket Tools

    SecureAuth. (n.d.). Retrieved January 15, 2019.

    Open source URL
  10. [10]
    Github PowerShell Empire

    Schroeder, W., Warner, J., Nelson, M. (n.d.). Github PowerShellEmpire. Retrieved April 28, 2016.

    Open source URL
  11. [11]
    CISA Leviathan 2024

    CISA et al. (2024, July 8). People’s Republic of China (PRC) Ministry of State Security APT40 Tradecraft in Action. Retrieved February 3, 2025.

    Open source URL
  12. [12]
    DFIR Ryuk's Return October 2020

    The DFIR Report. (2020, October 8). Ryuk’s Return. Retrieved October 9, 2020.

    Open source URL
  13. [13]
    FireEye KEGTAP SINGLEMALT October 2020

    Kimberly Goody, Jeremy Kennelly, Joshua Shilko, Steve Elovitz, Douglas Bienstock. (2020, October 28). Unhappy Hour Special: KEGTAP and SINGLEMALT With a Ransomware Chaser. Retrieved October 28, 2020.

    Open source URL
  14. [14]
    DHS/CISA Ransomware Targeting Healthcare October 2020

    DHS/CISA. (2020, October 28). Ransomware Activity Targeting the Healthcare and Public Health Sector. Retrieved October 28, 2020.

    Open source URL
  15. [15]
    DFIR Ryuk 2 Hour Speed Run November 2020

    The DFIR Report. (2020, November 5). Ryuk Speed Run, 2 Hours to Ransom. Retrieved November 6, 2020.

    Open source URL
  16. [16]
    Mandiant FIN12 Oct 2021

    Shilko, J., et al. (2021, October 7). FIN12: The Prolific Ransomware Intrusion Threat Actor That Has Aggressively Pursued Healthcare Targets. Retrieved June 15, 2023.

    Open source URL
  17. [17]
    FoxIT Wocao December 2019

    Dantzig, M. v., Schamper, E. (2019, December 19). Operation Wocao: Shining a light on one of China’s hidden hacking groups. Retrieved October 8, 2020.

    Open source URL
  18. [18]
    GitHub SILENTTRINITY Modules July 2019

    Salvati, M. (2019, August 6). SILENTTRINITY Modules. Retrieved March 24, 2022.

    Open source URL
  19. [19]
    Microsoft Deep Dive Solorigate January 2021

    MSTIC, CDOC, 365 Defender Research Team. (2021, January 20). Deep dive into the Solorigate second-stage activation: From SUNBURST to TEARDROP and Raindrop . Retrieved January 22, 2021.

    Open source URL
  20. [20]
    PowerSploit Invoke Kerberoast

    Schroeder, W. & Hart M. (2016, October 31). Invoke-Kerberoast. Retrieved March 23, 2018.

    Open source URL
  21. [21]
    CrowdStrike Carbon Spider August 2021

    Loui, E. and Reynolds, J. (2021, August 30). CARBON SPIDER Embraces Big Game Hunting, Part 1. Retrieved September 20, 2021.

    Open source URL
  22. [22]
    Mandiant FIN7 Apr 2022

    Abdo, B., et al. (2022, April 4). FIN7 Power Hour: Adversary Archaeology and the Evolution of FIN7. Retrieved April 5, 2022.

    Open source URL
  23. [23]
    Mandiant_UNC2165

    Mandiant Intelligence. (2022, June 2). To HADES and Back: UNC2165 Shifts to LOCKBIT to Evade Sanctions. Retrieved July 29, 2024.

    Open source URL
  24. [24]
    Palo Alto Brute Ratel July 2022

    Harbison, M. and Renals, P. (2022, July 5). When Pentest Tools Go Brutal: Red-Teaming Tool Being Abused by Malicious Actors. Retrieved February 1, 2023.

    Open source URL
  25. [25]
    AdSecurity Cracking Kerberos Dec 2015

    Metcalf, S. (2015, December 31). Cracking Kerberos TGS Tickets Using Kerberoast – Exploiting Kerberos to Compromise the Active Directory Domain. Retrieved March 22, 2018.

    Open source URL
  26. [26]
    AdSecurity Cracking Kerberos Dec 2015

    Metcalf, S. (2015, December 31). Cracking Kerberos TGS Tickets Using Kerberoast – Exploiting Kerberos to Compromise the Active Directory Domain. Retrieved March 22, 2018.

    Open source URL
  27. [27]
    Empire InvokeKerberoast Oct 2016

    EmpireProject. (2016, October 31). Invoke-Kerberoast.ps1. Retrieved March 22, 2018.

    Open source URL
  28. [28]
    Empire InvokeKerberoast Oct 2016

    EmpireProject. (2016, October 31). Invoke-Kerberoast.ps1. Retrieved March 22, 2018.

    Open source URL
  29. [29]
    Harmj0y Kerberoast Nov 2016

    Schroeder, W. (2016, November 1). Kerberoasting Without Mimikatz. Retrieved September 23, 2024.

    Open source URL
  30. [30]
    Harmj0y Kerberoast Nov 2016

    Schroeder, W. (2016, November 1). Kerberoasting Without Mimikatz. Retrieved September 23, 2024.

    Open source URL
  31. [31]
    Microsoft Detecting Kerberoasting Feb 2018

    Bani, M. (2018, February 23). Detecting Kerberoasting activity using Azure Security Center. Retrieved March 23, 2018.

    Open source URL
  32. [32]
    Microsoft Detecting Kerberoasting Feb 2018

    Bani, M. (2018, February 23). Detecting Kerberoasting activity using Azure Security Center. Retrieved March 23, 2018.

    Open source URL
  33. [33]
    Microsoft SPN

    Microsoft. (n.d.). Service Principal Names. Retrieved March 22, 2018.

    Open source URL
  34. [34]
    Microsoft SPN

    Microsoft. (n.d.). Service Principal Names. Retrieved March 22, 2018.

    Open source URL
  35. [35]
    Microsoft SetSPN

    Microsoft. (2010, April 13). Service Principal Names (SPNs) SetSPN Syntax (Setspn.exe). Retrieved March 22, 2018.

    Open source URL
  36. [36]
    Microsoft SetSPN

    Microsoft. (2010, April 13). Service Principal Names (SPNs) SetSPN Syntax (Setspn.exe). Retrieved March 22, 2018.

    Open source URL
  37. [37]
    SANS Attacking Kerberos Nov 2014

    Medin, T. (2014, November). Attacking Kerberos - Kicking the Guard Dog of Hades. Retrieved March 22, 2018.

    Open source URL
  38. [38]
    SANS Attacking Kerberos Nov 2014

    Medin, T. (2014, November). Attacking Kerberos - Kicking the Guard Dog of Hades. Retrieved March 22, 2018.

    Open source URL
  39. [39]
    mitre-attackT1558.003
    Open source URL
  40. [40]
    mitre-attackT1558.003
    Open source URL
  41. [41]
    mitre-attackT1558.003
    Open source URL
  42. [42]
    GitHub Rubeus March 2023

    Harmj0y. (n.d.). Rubeus. Retrieved March 29, 2023.

    Open source URL
  43. [43]
    AdSecurity Cracking Kerberos Dec 2015

    Metcalf, S. (2015, December 31). Cracking Kerberos TGS Tickets Using Kerberoast – Exploiting Kerberos to Compromise the Active Directory Domain. Retrieved March 22, 2018.

    Open source URL
  44. [44]
    AdSecurity Cracking Kerberos Dec 2015

    Metcalf, S. (2015, December 31). Cracking Kerberos TGS Tickets Using Kerberoast – Exploiting Kerberos to Compromise the Active Directory Domain. Retrieved March 22, 2018.

    Open source URL
  45. [45]
    Impacket Tools

    SecureAuth. (n.d.). Retrieved January 15, 2019.

    Open source URL
  46. [46]
    Github PowerShell Empire

    Schroeder, W., Warner, J., Nelson, M. (n.d.). Github PowerShellEmpire. Retrieved April 28, 2016.

    Open source URL
  47. [47]
    CISA Leviathan 2024

    CISA et al. (2024, July 8). People’s Republic of China (PRC) Ministry of State Security APT40 Tradecraft in Action. Retrieved February 3, 2025.

    Open source URL
  48. [48]
    DFIR Ryuk 2 Hour Speed Run November 2020

    The DFIR Report. (2020, November 5). Ryuk Speed Run, 2 Hours to Ransom. Retrieved November 6, 2020.

    Open source URL
  49. [49]
    DFIR Ryuk's Return October 2020

    The DFIR Report. (2020, October 8). Ryuk’s Return. Retrieved October 9, 2020.

    Open source URL
  50. [50]
    DHS/CISA Ransomware Targeting Healthcare October 2020

    DHS/CISA. (2020, October 28). Ransomware Activity Targeting the Healthcare and Public Health Sector. Retrieved October 28, 2020.

    Open source URL
  51. [51]
    FireEye KEGTAP SINGLEMALT October 2020

    Kimberly Goody, Jeremy Kennelly, Joshua Shilko, Steve Elovitz, Douglas Bienstock. (2020, October 28). Unhappy Hour Special: KEGTAP and SINGLEMALT With a Ransomware Chaser. Retrieved October 28, 2020.

    Open source URL
  52. [52]
    Mandiant FIN12 Oct 2021

    Shilko, J., et al. (2021, October 7). FIN12: The Prolific Ransomware Intrusion Threat Actor That Has Aggressively Pursued Healthcare Targets. Retrieved June 15, 2023.

    Open source URL
  53. [53]
    FoxIT Wocao December 2019

    Dantzig, M. v., Schamper, E. (2019, December 19). Operation Wocao: Shining a light on one of China’s hidden hacking groups. Retrieved October 8, 2020.

    Open source URL
  54. [54]
    GitHub SILENTTRINITY Modules July 2019

    Salvati, M. (2019, August 6). SILENTTRINITY Modules. Retrieved March 24, 2022.

    Open source URL
  55. [55]
    Microsoft Deep Dive Solorigate January 2021

    MSTIC, CDOC, 365 Defender Research Team. (2021, January 20). Deep dive into the Solorigate second-stage activation: From SUNBURST to TEARDROP and Raindrop . Retrieved January 22, 2021.

    Open source URL
  56. [56]
    Harmj0y Kerberoast Nov 2016

    Schroeder, W. (2016, November 1). Kerberoasting Without Mimikatz. Retrieved September 23, 2024.

    Open source URL
  57. [57]
    Harmj0y Kerberoast Nov 2016

    Schroeder, W. (2016, November 1). Kerberoasting Without Mimikatz. Retrieved September 23, 2024.

    Open source URL
  58. [58]
    PowerSploit Invoke Kerberoast

    Schroeder, W. & Hart M. (2016, October 31). Invoke-Kerberoast. Retrieved March 23, 2018.

    Open source URL
  59. [59]
    AdSecurity Cracking Kerberos Dec 2015

    Metcalf, S. (2015, December 31). Cracking Kerberos TGS Tickets Using Kerberoast – Exploiting Kerberos to Compromise the Active Directory Domain. Retrieved March 22, 2018.

    Open source URL
  60. [60]
    AdSecurity Cracking Kerberos Dec 2015

    Metcalf, S. (2015, December 31). Cracking Kerberos TGS Tickets Using Kerberoast – Exploiting Kerberos to Compromise the Active Directory Domain. Retrieved March 22, 2018.

    Open source URL
  61. [61]
    AdSecurity Cracking Kerberos Dec 2015

    Metcalf, S. (2015, December 31). Cracking Kerberos TGS Tickets Using Kerberoast – Exploiting Kerberos to Compromise the Active Directory Domain. Retrieved March 22, 2018.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.