Detailedseverity: HighStable
CAPEC-509Kerberoasting
Abstraction
Detailed
Status
Stable
Severity
High
Description
Through the exploitation of how service accounts leverage Kerberos authentication with Service Principal Names (SPNs), the adversary obtains and subsequently cracks the hashed credentials of a service account target to exploit its privileges. The Kerberos authentication protocol centers around a ticketing system which is used to request/grant access to services and to then access the requested services. As an authenticated user, the adversary may request Active Directory and obtain a service ticket with portions encrypted via RC4 with the private key of the authenticated account. By extracting the local ticket and saving it disk, the adversary can brute force the hashed value to reveal the target account credentials.
Related weaknesses· 7
MITRE ATT&CK crosswalk· 1
Related attack patterns· 2
Exploits7
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Authentication Bypass by Capture-replaycwe-294 | 100% | live |
| Weakness | Weak Password Requirementscwe-521 | 100% | live |
| Weakness | Not Using Password Agingcwe-262 | 100% | live |
| Weakness | Password Aging with Long Expirationcwe-263 | 100% | live |
| Weakness | Use of Single-factor Authenticationcwe-308 | 100% | live |
| Weakness | Insufficiently Protected Credentialscwe-522 | 100% | live |
| Weakness | Use of Password System for Primary Authenticationcwe-309 | 100% | live |
Related to1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| SubTechnique | Kerberoastingt1558.003 | 100% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.