logo

A Toast to Kerberoast

ID: 72b330b9-5e27-593d-8487-a8faacdbc2db

STIX ID: report--72b330b9-5e27-593d-8487-a8faacdbc2db

Feed Name: Black Hills Infosec Blog

Date Published: 2017-05-08

Date Updated: 2026-04-27

Author: BHIS

...
...

This blog-style walkthrough details how an attacker can remotely perform Kerberoasting via an established Meterpreter session to a Linux C2, using proxychains and Impacket to collect service Principal Name (SPN) Kerberos tickets and Hashcat to crack them offline; it includes example commands, optional post-exploitation steps (secretsdump), and recommends mitigating by enforcing long, frequently rotated service account passwords.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.