Microsoft’s guidance to help mitigate Kerberoasting
ID: 6c29f2dc-d75d-529d-ba1c-b9dbea50cffe
STIX ID: report--6c29f2dc-d75d-529d-ba1c-b9dbea50cffe
Feed Name: Microsoft Security
This Microsoft Security blog explains Kerberoasting, a Kerberos-based Active Directory attack where an adversary with a valid account requests service tickets and cracks them offline to obtain service-account credentials for lateral movement and privilege escalation. It outlines the risks, detection strategies (monitoring unusual Kerberos encryption types and repeated service ticket requests), and prescriptive mitigations including using gMSA/dMSA, enforcing AES ticket encryption, applying long random passwords, and auditing/removing unnecessary SPNs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
