logo

Is Kerberoasting Still a Risk When AES-256 Kerberos Encryption Is Enabled?

ID: f5105225-5b86-5396-8e08-96f75f5adce7

STIX ID: report--f5105225-5b86-5396-8e08-96f75f5adce7

Feed Name: SpecterOps Blog

Date Published: 2025-10-21

Date Updated: 2026-04-30

Author: Elad Shamir

...
...

This post explains that Kerberoasting remains a viable attack against AD service accounts with SPNs even in AES‑256-only environments, because attackers can perform offline dictionary/rules-based cracking against ticket material derived from weak passwords. With RC4 deprecated and AES slowing but not stopping cracking, the author emphasizes enforcing strong, random service account passwords (or managed accounts) as the primary defense rather than relying on encryption type.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.