Kerberoasting
Kerberoasting is a technique that exploits the Kerberos protocol to extract NTLM hashes from service account credentials, enabling attackers to attempt password recovery. This attack targets service principal names (SPNs) configured for services like SQL Server, IIS, or LDAP, which often have weak or default passwords. By leveraging the Kerberos authentication process, an attacker can request a Ticket Granting Service (TGS) ticket for a service account and then extract the encrypted hash, which can be cracked offline.
Attack Process Overview¶
-
Target Identification:
The attacker identifies service accounts with SPNs that are accessible to the attacker’s domain credentials. These accounts are often misconfigured or use default passwords. -
AS-REQ Request:
The attacker sends an Authentication Request (AS-REQ) to the Key Distribution Center (KDC) to obtain a Ticket Granting Ticket (TGT). This step typically requires valid domain credentials (e.g., viamimikatzorRubeus). -
TGS Ticket Request:
Using the TGT, the attacker requests a Ticket Granting Service (TGS) ticket for a specific SPN (e.g.,SQLSvc/SQLServer). The TGS ticket is encrypted with the service account’s password hash. -
Hash Extraction:
The attacker saves the TGS ticket (e.g.,SQLSvc_SQLServer.kirbi) and uses tools likehashcatorJohn the Ripperto crack the encrypted hash. Since the ticket is encrypted with the service account’s password, successful cracking grants access to the service.
Tools and Commands¶
1. CrackMapExec (CME)¶
This command requests TGS tickets for all SPNs associated with the target domain. The output includes the encrypted hash.2. Impacket's kerberoast Module¶
from impacket.krb5 import kerberosv5
from impacket.krb5.asn1 import TGSRep
# Example: Request TGS ticket for a specific SPN
realm = 'EXAMPLE.COM'
spn = 'HTTP/localhost'
tgt = ... # Pre-obtained TGT
context = kerberosv5.Kerberos5Context()
ccache = kerberosv5.CCache()
ccache.addTicket(tgt)
tgs, cipher, _ = context.getTGS(spn, realm, ccache)
tgs object contains the encrypted hash, which can be exported for offline cracking.
3. Mimikatz (Windows)¶
Mimikatz can enumerate SPNs and export TGS tickets for further analysis.Mitigations and Considerations¶
- Strong Passwords: Service accounts should use complex, unique passwords.
- Disable Unnecessary SPNs: Minimize the number of SPNs configured to reduce attack surface.
- Kerberos Pre-Authentication: Enabling Kerberos pre-authentication (via
msDS-UserAccountControl) prevents attackers from requesting TGS tickets without proving their password. - Monitoring: Regularly audit Kerberos ticket requests and detect anomalous SPN usage.
Key takeaways¶
- Kerberoasting exploits weak service account passwords by extracting NTLM hashes from TGS tickets.
- Attackers use tools like
CrackMapExecorImpacketto request and crack these hashes. - Mitigations include enforcing strong passwords, disabling unused SPNs, and enabling Kerberos pre-authentication.
- The attack highlights the importance of securing service accounts and monitoring Kerberos activity.