FORENSIA

ATT&CK · T1558.003 · sub-technique

Kerberoasting

Tactics: credential-access

About

Adversaries may abuse a valid Kerberos ticket-granting ticket (TGT) or sniff network traffic to obtain a ticket-granting service (TGS) ticket that may be vulnerable to Brute Force. Service principal names (SPNs) are used to uniquely identify each instance of a Windows service. To enable authentication, Kerberos requires that SPNs be associated with at least one service logon account (an account specifically tasked with running a service). Adversaries possessing a valid Kerberos ticket-granting ticket (TGT) may request one or more Kerberos ticket-granting service (TGS) service tickets for any SPN from a domain controller (DC). Portions of these tickets may be encrypted with the RC4 algorithm, meaning the Kerberos 5 TGS-REP etype 23 hash of the service account associated with the SPN is used as the private key and is thus vulnerable to offline Brute Force attacks that may expose plaintext credentials. This same behavior could be executed using service tickets captured from network traffic. Cracked hashes may enable Persistence, Privilege Escalation, and Lateral Movement via access to Valid Accounts.

Used by actors

3 known groups

Software

6 malware/tools implement this

PowerSploitImpacketEmpireSILENTTRINITYBrute Ratel C4Rubeus

Corpus indicators tagged with this technique

143 indicators in the corpus carry T1558.003.

IndicatorTypeFamilySevSrc
cve-2025-68670cve852
7f776ad200287d6de14a29158c457179hash801
db972979d508e75fe730d3b72c2701470fbdaeaf8ebdd674744754fa44438ca5sha256ransomware801
5329f7bff9d0d5db28821b86c26d628fhash801
7242ac065b50bcde9308756b49dbadcbhash801
2cabb721681455dae1b6a26709def453hash801
2758f4d71a2a2dfdefab81737c2d776b2a3dafe5844fdd2157e089a28447ca98sha256phishing801
369b75bdcded16469ede7ab8bedcfae1hash801
9eaa577c8ba71646928c1c34c3145536b0498f65f26060a6ba00744bcef57644sha256phishing801
874bcb1c3d050a5b5b333a2198f504fcb27927c2abdd43b07440188a380c52d5sha256phishing801
36120f5e9411bcbac7104ef3fa964ed2hash801
493b901d1b33eb577db64aadd948f9cehash801
28ecf8fb6719e14231b94b4d37629b0ehash801
2aa1e9765ef6b00b94a9b6be0041436ahash801
51f7f794ed43fb90d0f8ebbb5effe628hash801
f591275a8f014b29e567529d67c54eb7bb4473db1c38737d6bfd5b3d52c9344esha256ransomware801
3f797a639bc855bc6d5471f327924b62d10900ddec49b970eca6604142bbb4besha256ransomware801
67d7e3aeeb673bf60c59361c12a4ed81hash801
59e3c4cb06331b4f2d78a9a0592f3747e573bd01c5a7650c26361d1e25520712sha256ransomware801
38353f95fff270f4e3a9d7add8c64666020dd668ce66e15969a736ec48cadc59sha256phishing801
4253dd1a4c0867b0be7732f75b2f630cebfb7fed94270e15fb3b12ae40546d01sha256phishing801
479ae5fd7274439ddfa27bc03298ebfdfc5ff17f6412acccf74d4dbd90d94218sha256phishing801
216cb7f31d383c0dd892b284df05a495hash801
0320dd389fdbab25d46792bd2817675ehash802
1b39e86eb772a0e40060b672b7f574f1hash801
0857c84b62289a1a9f29e19244e9a499hash802
34d798a6c55e57ed0932b6499f4fbcb5454bdfca903307be101a0594b0ac07bcsha256ransomware801
25c8ed0511375dca57ef136ac3fa0ccahash801
8c935feec4bd05d5d918df308be417532fb42608fb989a08eab183e0ae699235sha256ransomware801
7a95360b7e0eb5b107a3d231abbc541ahash801

Showing the top 30 by severity of 143.