logo

Microsoft’s guidance to help mitigate Kerberoasting  

ID: 6c29f2dc-d75d-529d-ba1c-b9dbea50cffe

STIX ID: report--6c29f2dc-d75d-529d-ba1c-b9dbea50cffe

Feed Name: Microsoft Security

Threat Score
65/100

Date Published: 2024-10-11

Date Updated: 2026-04-28

Author: David Weston

...
...

This Microsoft Security blog explains Kerberoasting, a Kerberos-based Active Directory attack where an adversary with a valid account requests service tickets and cracks them offline to obtain service-account credentials for lateral movement and privilege escalation. It outlines the risks, detection strategies (monitoring unusual Kerberos encryption types and repeated service ticket requests), and prescriptive mitigations including using gMSA/dMSA, enforcing AES ticket encryption, applying long random passwords, and auditing/removing unnecessary SPNs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.