logo

Kerberoasting in 2025: How to protect your service accounts

ID: 0d12cdb8-72c4-5ded-a4ec-f4e2ee30d8cd

STIX ID: report--0d12cdb8-72c4-5ded-a4ec-f4e2ee30d8cd

Feed Name: Bleeping Computer

Date Published: 2025-11-13

Date Updated: 2026-07-17

Author: Sponsored by Specops Software

...
...

This article explains Kerberoasting — a Kerberos-based Active Directory attack where adversaries request service tickets tied to service principal names (SPNs), take the tickets offline, and brute-force the password-derived encryption to compromise service accounts and escalate privileges. It highlights detection difficulties (offline cracking, no malware required) and recommends defenses: audit SPN accounts, enforce very long/rotated passwords, use Group Managed Service Accounts (gMSAs), prefer AES encryption, and apply MFA and continuous password-policy controls; the piece is sponsored by Specops Software.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.