Azure AD Kerberos Tickets: Pivoting to the Cloud
ID: e74079f1-e4d5-56a0-8d4b-b47a3551969f
STIX ID: report--e74079f1-e4d5-56a0-8d4b-b47a3551969f
Feed Name: TrustedSec blog
This report demonstrates a practical attack path in hybrid Azure AD environments where an attacker who extracts the AZUREADSSOACC$ machine account NTLM hash and on-prem SIDs can use AADInternals and ROADtools to request Kerberos tickets, obtain Azure AD tokens, impersonate service accounts (including AD Sync), elevate to global administrator, create users, and gain subscription-owner access—achieving full cloud compromise and persistence even if on-premises passwords are changed; the report recommends rotating the AZUREADSSOACC$ key and enforcing conditional access for service accounts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
