Kerberoasting in 2025: How to protect your service accounts
ID: 0d12cdb8-72c4-5ded-a4ec-f4e2ee30d8cd
STIX ID: report--0d12cdb8-72c4-5ded-a4ec-f4e2ee30d8cd
Feed Name: Bleeping Computer
This article explains Kerberoasting — a Kerberos-based Active Directory attack where adversaries request service tickets tied to service principal names (SPNs), take the tickets offline, and brute-force the password-derived encryption to compromise service accounts and escalate privileges. It highlights detection difficulties (offline cracking, no malware required) and recommends defenses: audit SPN accounts, enforce very long/rotated passwords, use Group Managed Service Accounts (gMSAs), prefer AES encryption, and apply MFA and continuous password-policy controls; the piece is sponsored by Specops Software.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
