#kerberoasting — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #kerberoasting, aggregated by home.social.
-
Extract Kerberos TGS tickets in-memory with PowerShell, no disk writes. Uses KerberosRequestorSecurityToken to request tickets for SPNs via ADSI, enabling stealthy kerberoasting one-liners. Runs on Windows 10/11, Server 2016+. #kerberoasting #powershell #stealth
https://www.valtersit.com/vault/extract-kerberos-tickets-with-powershell-for-stealthy-execut-81f2d2/
-
Extract Kerberos TGS tickets in-memory with PowerShell, no disk writes. Uses KerberosRequestorSecurityToken to request tickets for SPNs via ADSI, enabling stealthy kerberoasting one-liners. Runs on Windows 10/11, Server 2016+. #kerberoasting #powershell #stealth
https://www.valtersit.com/vault/extract-kerberos-tickets-with-powershell-for-stealthy-execut-81f2d2/
-
Monitor Windows Event ID 4769 to detect Kerberoasting. This PowerShell script queries Security logs for service account requests (ServiceName with $) using RC4 (0x17) or AES256 (0x12) encryption, flagging multiple requests from the same source IP. Works on Windows Server 2019/2022, Win10 22H2. #kerberoasting #detection #ValtersIT
https://www.valtersit.com/vault/detect-kerberoasting-with-windows-event-id-4769-c2115a/
-
Как я инфру в буткемпе на Standoff365 проходил [Infra 1] — [Infra 12]
Изначально хотел написать каждый пост для отдельного задания в инфре, но некоторые задания настолько короткие, что писать там даже особо нечего, тем более подсказки в буткемпе очень сильно облегчают решение. Начнем с первой инфры.
https://habr.com/ru/articles/1043364/
#standoff_365 #ctf #infrastructure #windows #activedirectory #kerberoasting #impacket #hash #c2 #adaptix
-
Как я инфру в буткемпе на Standoff365 проходил [Infra 1] — [Infra 12]
Изначально хотел написать каждый пост для отдельного задания в инфре, но некоторые задания настолько короткие, что писать там даже особо нечего, тем более подсказки в буткемпе очень сильно облегчают решение. Начнем с первой инфры.
https://habr.com/ru/articles/1043364/
#standoff_365 #ctf #infrastructure #windows #activedirectory #kerberoasting #impacket #hash #c2 #adaptix
-
Как я инфру в буткемпе на Standoff365 проходил [Infra 1] — [Infra 12]
Изначально хотел написать каждый пост для отдельного задания в инфре, но некоторые задания настолько короткие, что писать там даже особо нечего, тем более подсказки в буткемпе очень сильно облегчают решение. Начнем с первой инфры.
https://habr.com/ru/articles/1043364/
#standoff_365 #ctf #infrastructure #windows #activedirectory #kerberoasting #impacket #hash #c2 #adaptix
-
----------------
🚨 Incident Response
===================Most Akira ransomware write-ups focus on the ransom note or encryption routine. This reconstruction starts earlier, using only two log sources that almost never get correlated: perimeter firewall syslog and Windows EVTX exports. No EDR, no PCAP, no proxy logs.
Initial Access
Filtering SSLVPN authentication events for 72 hours before encryption revealed a brute-force pattern against a single local SSLVPN account. The account had been disabled in Active Directory but remained provisioned as a local firewall user. No MFA was configured.
Two details stand out. The brute force originated from a single hosting-provider IP. One IPS rule or geo-block would have stopped it. After the successful credential match, the attacker entered immediately with no pause. That behavioral fingerprint points to credential stuffing against a known target rather than spray-and-pray.
Discovery
Firewall NAT logs provided the post-VPN source IP. Correlating that IP with Windows Security EID 4624 logons identified a jump host used by legitimate remote administrators. All subsequent discovery was visible through EID 4688 process creation events:
• explorer.exe → cmd.exe
• cmd.exe → nltest.exe /dclist:
• cmd.exe → net.exe group "Domain Admins" /domain
• cmd.exe → net.exe group "Enterprise Admins" /domain
• cmd.exe → whoami.exe /all
• cmd.exe → renamed binary matching AdFind.exe behaviorCredential Access
Approximately 24 hours after discovery, a cluster of EID 4769 events appeared against three service accounts. All RC4-encrypted, all from the jump host, all inside a 90-second window. This is the signature pattern for Kerberoasting. It is also one of the cheapest detections any AD-joined organization can deploy.
Key Takeaways
1. Perimeter syslog and Windows event channels produce high-fidelity kill chain timelines even without EDR.
2. The deprovisioning gap between AD and local firewall accounts was the initial entry vector.
3. Single-source-IP brute force is detectable with basic IPS or geo-blocking.
4. Kerberoasting detection via EID 4769 (RC4 + service account + tight time window) requires no specialized tooling.🔹 DFIR #Akira #Kerberoasting #IncidentResponse #EVTX
🔗 Source: https://isc.sans.edu/diary/rss/33024
-
Kerbrute: Enumerating Active Directory Accounts
In this article, I cover how Kerberoasting works, common attack techniques, detection methods, and practical defense strategies.
🔗 https://denizhalil.com/2026/05/21/kerberoasting-attack-defense-guide/
#CyberSecurity #ActiveDirectory #Kerberoasting #Kerberos #CredentialAccess #RedTeam #BlueTeam #Pentesting #WindowsSecurity #InfoSec #ThreatDetection #DenizHalil
-
Kerbrute: Enumerating Active Directory Accounts
In this article, I cover how Kerberoasting works, common attack techniques, detection methods, and practical defense strategies.
🔗 https://denizhalil.com/2026/05/21/kerberoasting-attack-defense-guide/
#CyberSecurity #ActiveDirectory #Kerberoasting #Kerberos #CredentialAccess #RedTeam #BlueTeam #Pentesting #WindowsSecurity #InfoSec #ThreatDetection #DenizHalil
-
Basic Active Directory Enumeration: A Comprehensive Guide
In this article, I cover how Kerberoasting works, common attack techniques, detection methods, and practical defense strategies.
https://denizhalil.com/2025/05/05/basic-active-directory-enumeration-a-comprehensive-guide/#CyberSecurity #ActiveDirectory #Kerberoasting #Kerberos #CredentialAccess #RedTeam #BlueTeam #Pentesting #WindowsSecurity #InfoSec #ThreatDetection #DenizHalil
-
Basic Active Directory Enumeration: A Comprehensive Guide
In this article, I cover how Kerberoasting works, common attack techniques, detection methods, and practical defense strategies.
https://denizhalil.com/2025/05/05/basic-active-directory-enumeration-a-comprehensive-guide/#CyberSecurity #ActiveDirectory #Kerberoasting #Kerberos #CredentialAccess #RedTeam #BlueTeam #Pentesting #WindowsSecurity #InfoSec #ThreatDetection #DenizHalil
-
Basic Active Directory Enumeration: A Comprehensive Guide
In this article, I cover how Kerberoasting works, common attack techniques, detection methods, and practical defense strategies.
https://denizhalil.com/2025/05/05/basic-active-directory-enumeration-a-comprehensive-guide/#CyberSecurity #ActiveDirectory #Kerberoasting #Kerberos #CredentialAccess #RedTeam #BlueTeam #Pentesting #WindowsSecurity #InfoSec #ThreatDetection #DenizHalil
-
What is Kerberoasting Attack – Kerberoasting: A Comprehensive Guide
In this article, I cover how Kerberoasting works, common attack techniques, detection methods, and practical defense strategies.
https://denizhalil.com/2026/05/21/kerberoasting-attack-defense-guide/#CyberSecurity #ActiveDirectory #Kerberoasting #Kerberos #CredentialAccess #RedTeam #BlueTeam #Pentesting #WindowsSecurity #InfoSec #ThreatDetection #DenizHalil
-
What is Kerberoasting Attack – Kerberoasting: A Comprehensive Guide
In this article, I cover how Kerberoasting works, common attack techniques, detection methods, and practical defense strategies.
https://denizhalil.com/2026/05/21/kerberoasting-attack-defense-guide/#CyberSecurity #ActiveDirectory #Kerberoasting #Kerberos #CredentialAccess #RedTeam #BlueTeam #Pentesting #WindowsSecurity #InfoSec #ThreatDetection #DenizHalil
-
What is Kerberoasting Attack – Kerberoasting: A Comprehensive Guide
In this article, I cover how Kerberoasting works, common attack techniques, detection methods, and practical defense strategies.
https://denizhalil.com/2026/05/21/kerberoasting-attack-defense-guide/#CyberSecurity #ActiveDirectory #Kerberoasting #Kerberos #CredentialAccess #RedTeam #BlueTeam #Pentesting #WindowsSecurity #InfoSec #ThreatDetection #DenizHalil
-
Страшно, когда не видно: взгляд внутрь домена
Привет, Хабр! Меня зовут Данил Зарипов, я занимаюсь продуктовой экспертизой в Positive Technologies. Эту статью мне помог подготовить мой коллега Кирилл Маслов — наш эксперт по направлению Asset Management. Мы решили не искать лёгких путей и выбрали тему, которая большинству из вас хорошо знакома. Казалось бы, что нового можно сказать про домены, пусть и с точки зрения безопасности? Для атакующего захват домена — это фактически победа. Получив контроль над контроллером домена, злоумышленник получает доступ ко всем учетным записям, компьютерам, групповым политикам и доверительным отношениям, а дальше дело техники: найти учетки бухгалтеров и топ-менеджеров, переключиться на их машины, читать почту, копировать документы. Это самые безобидные последствия. Как это часто бывает в информационной безопасности, самое знакомое скрывает множество нюансов. Давайте разбираться!
https://habr.com/ru/companies/pt/articles/1027070/
#захват_домена #domain_controller #kerberoasting #krbtgt #rsat #shadow_it #max_patrol_vm #hcc #siem #carbon
-
Страшно, когда не видно: взгляд внутрь домена
Привет, Хабр! Меня зовут Данил Зарипов, я занимаюсь продуктовой экспертизой в Positive Technologies. Эту статью мне помог подготовить мой коллега Кирилл Маслов — наш эксперт по направлению Asset Management. Мы решили не искать лёгких путей и выбрали тему, которая большинству из вас хорошо знакома. Казалось бы, что нового можно сказать про домены, пусть и с точки зрения безопасности? Для атакующего захват домена — это фактически победа. Получив контроль над контроллером домена, злоумышленник получает доступ ко всем учетным записям, компьютерам, групповым политикам и доверительным отношениям, а дальше дело техники: найти учетки бухгалтеров и топ-менеджеров, переключиться на их машины, читать почту, копировать документы. Это самые безобидные последствия. Как это часто бывает в информационной безопасности, самое знакомое скрывает множество нюансов. Давайте разбираться!
https://habr.com/ru/companies/pt/articles/1027070/
#захват_домена #domain_controller #kerberoasting #krbtgt #rsat #shadow_it #max_patrol_vm #hcc #siem #carbon
-
Страшно, когда не видно: взгляд внутрь домена
Привет, Хабр! Меня зовут Данил Зарипов, я занимаюсь продуктовой экспертизой в Positive Technologies. Эту статью мне помог подготовить мой коллега Кирилл Маслов — наш эксперт по направлению Asset Management. Мы решили не искать лёгких путей и выбрали тему, которая большинству из вас хорошо знакома. Казалось бы, что нового можно сказать про домены, пусть и с точки зрения безопасности? Для атакующего захват домена — это фактически победа. Получив контроль над контроллером домена, злоумышленник получает доступ ко всем учетным записям, компьютерам, групповым политикам и доверительным отношениям, а дальше дело техники: найти учетки бухгалтеров и топ-менеджеров, переключиться на их машины, читать почту, копировать документы. Это самые безобидные последствия. Как это часто бывает в информационной безопасности, самое знакомое скрывает множество нюансов. Давайте разбираться!
https://habr.com/ru/companies/pt/articles/1027070/
#захват_домена #domain_controller #kerberoasting #krbtgt #rsat #shadow_it #max_patrol_vm #hcc #siem #carbon
-
#Kerberoasting im Windows Netzwerk - wie man sich schützt
-
#Kerberoasting im Windows Netzwerk - wie man sich schützt
-
#Kerberoasting im Windows Netzwerk - wie man sich schützt
-
#Kerberoasting im Windows Netzwerk - wie man sich schützt
-
#Kerberoasting im Windows Netzwerk - wie man sich schützt
-
How weak passwords and other failings led to catastrophic breach of Ascension - Last week, a prominent US senator called on the Federal Trad... - https://arstechnica.com/security/2025/09/how-weak-passwords-and-other-failings-led-to-catastrophic-breach-of-ascension/ #activedirectory #networkbreaches #kerberoasting #ransomware #features #security #kerberos #biz&it
-
How weak passwords and other failings led to catastrophic breach of Ascension - Last week, a prominent US senator called on the Federal Trad... - https://arstechnica.com/security/2025/09/how-weak-passwords-and-other-failings-led-to-catastrophic-breach-of-ascension/ #activedirectory #networkbreaches #kerberoasting #ransomware #features #security #kerberos #biz&it
-
How weak passwords and other failings led to catastrophic breach of Ascension - Last week, a prominent US senator called on the Federal Trad... - https://arstechnica.com/security/2025/09/how-weak-passwords-and-other-failings-led-to-catastrophic-breach-of-ascension/ #activedirectory #networkbreaches #kerberoasting #ransomware #features #security #kerberos #biz&it
-
How weak passwords and other failings led to catastrophic breach of Ascension - Last week, a prominent US senator called on the Federal Trad... - https://arstechnica.com/security/2025/09/how-weak-passwords-and-other-failings-led-to-catastrophic-breach-of-ascension/ #activedirectory #networkbreaches #kerberoasting #ransomware #features #security #kerberos #biz&it
-
How weak passwords and other failings led to catastrophic breach of Ascension - Last week, a prominent US senator called on the Federal Trad... - https://arstechnica.com/security/2025/09/how-weak-passwords-and-other-failings-led-to-catastrophic-breach-of-ascension/ #activedirectory #networkbreaches #kerberoasting #ransomware #features #security #kerberos #biz&it
-
🚨 Kerberoasting: Still a Corporate Risk in 2025 🚨
🔑 Legacy protocols like RC4 in Active Directory leave doors wide open.
👤 Weak service account passwords make it worse.
💻 Attackers crack tickets offline at billions/sec, with zero alerts.This isn’t just a tech flaw — it’s a governance failure.
👉 Time to kill legacy crypto, enforce strong credentials, and build secure defaults that remove human error.Do read the insightful analysis by Prof. Matthew Green on the vulnerability at https://blog.cryptographyengineering.com/2025/09/10/kerberoasting/
#CyberSecurity #Kerberoasting #ActiveDirectory #InfoSec #Governance #RiskManagement #EnterpriseSecurity #Authentication
-
🚨 Kerberoasting: Still a Corporate Risk in 2025 🚨
🔑 Legacy protocols like RC4 in Active Directory leave doors wide open.
👤 Weak service account passwords make it worse.
💻 Attackers crack tickets offline at billions/sec, with zero alerts.This isn’t just a tech flaw — it’s a governance failure.
👉 Time to kill legacy crypto, enforce strong credentials, and build secure defaults that remove human error.Do read the insightful analysis by Prof. Matthew Green on the vulnerability at https://blog.cryptographyengineering.com/2025/09/10/kerberoasting/
#CyberSecurity #Kerberoasting #ActiveDirectory #InfoSec #Governance #RiskManagement #EnterpriseSecurity #Authentication
-
Kerberoasting Detections: A New Approach to a Decade-Old Challenge
In the article #kerberoasting is also shortly explained.
https://thehackernews.com/2025/07/kerberoasting-detections-new-approach.html
-
Kerberoasting Detections: A New Approach to a Decade-Old Challenge
In the article #kerberoasting is also shortly explained.
https://thehackernews.com/2025/07/kerberoasting-detections-new-approach.html
-
Kerberoasting Detections: A New Approach to a Decade-Old Challenge
In the article #kerberoasting is also shortly explained.
https://thehackernews.com/2025/07/kerberoasting-detections-new-approach.html
-
Kerberoasting Detections: A New Approach to a Decade-Old Challenge
In the article #kerberoasting is also shortly explained.
https://thehackernews.com/2025/07/kerberoasting-detections-new-approach.html
-
Kerberoasting Detections: A New Approach to a Decade-Old Challenge – Source:thehackernews.com https://ciso2ciso.com/kerberoasting-detections-a-new-approach-to-a-decade-old-challenge-sourcethehackernews-com/ #rssfeedpostgeneratorecho #CyberSecurityNews #Kerberoasting #TheHackerNews
-
Kerberoasting Detections: A New Approach to a Decade-Old Challenge – Source:thehackernews.com https://ciso2ciso.com/kerberoasting-detections-a-new-approach-to-a-decade-old-challenge-sourcethehackernews-com/ #rssfeedpostgeneratorecho #CyberSecurityNews #Kerberoasting #TheHackerNews
-
Kerberoasting Detections: A New Approach to a Decade-Old Challenge – Source:thehackernews.com https://ciso2ciso.com/kerberoasting-detections-a-new-approach-to-a-decade-old-challenge-sourcethehackernews-com/ #rssfeedpostgeneratorecho #CyberSecurityNews #Kerberoasting #TheHackerNews
-
Kerberoasting Detections: A New Approach to a Decade-Old Challenge – Source:thehackernews.com https://ciso2ciso.com/kerberoasting-detections-a-new-approach-to-a-decade-old-challenge-sourcethehackernews-com/ #rssfeedpostgeneratorecho #CyberSecurityNews #Kerberoasting #TheHackerNews
-
Обнаружение атаки Kerberoasting с использованием машинного обучения: от теории к практике
В эпоху стремительного роста угроз информационной безопасности защита корпоративных сетей становится критически важной. Одной из серьезных и довольно распространенных угроз является атака Kerberoasting, которая позволяет злоумышленнику, имеющему лишь базовые привилегии, извлечь хэш пароля сервисной учетной записи. В этой статье описывается, как методы машинного обучения помогают решению класса NTA обнаружить такую атаку в режиме реального времени. Дополнительно приводятся подробности реализации прототипа, экспериментальные результаты и ссылка на исходный код, опубликованный на GitHub.
https://habr.com/ru/articles/894216/
#kerberoasting #machine_learning #oneclass_svm #lof #kerberos
-
Обнаружение атаки Kerberoasting с использованием машинного обучения: от теории к практике
В эпоху стремительного роста угроз информационной безопасности защита корпоративных сетей становится критически важной. Одной из серьезных и довольно распространенных угроз является атака Kerberoasting, которая позволяет злоумышленнику, имеющему лишь базовые привилегии, извлечь хэш пароля сервисной учетной записи. В этой статье описывается, как методы машинного обучения помогают решению класса NTA обнаружить такую атаку в режиме реального времени. Дополнительно приводятся подробности реализации прототипа, экспериментальные результаты и ссылка на исходный код, опубликованный на GitHub.
https://habr.com/ru/articles/894216/
#kerberoasting #machine_learning #oneclass_svm #lof #kerberos
-
Обнаружение атаки Kerberoasting с использованием машинного обучения: от теории к практике
В эпоху стремительного роста угроз информационной безопасности защита корпоративных сетей становится критически важной. Одной из серьезных и довольно распространенных угроз является атака Kerberoasting, которая позволяет злоумышленнику, имеющему лишь базовые привилегии, извлечь хэш пароля сервисной учетной записи. В этой статье описывается, как методы машинного обучения помогают решению класса NTA обнаружить такую атаку в режиме реального времени. Дополнительно приводятся подробности реализации прототипа, экспериментальные результаты и ссылка на исходный код, опубликованный на GitHub.
https://habr.com/ru/articles/894216/
#kerberoasting #machine_learning #oneclass_svm #lof #kerberos
-
Kerberoasting (в т.ч. без пароля пользователя) + артефакты
🔥Атака Kerberoasting позволяет злоумышленнику захватить сервисную УЗ путём запроса TGS с указанием имени этой сервисной УЗ и последующим брутфорсом билета. А можно ли как-то провести атаку, не имея в арсенале доступ ни к одной доменной УЗ?
-
Kerberoasting (в т.ч. без пароля пользователя) + артефакты
🔥Атака Kerberoasting позволяет злоумышленнику захватить сервисную УЗ путём запроса TGS с указанием имени этой сервисной УЗ и последующим брутфорсом билета. А можно ли как-то провести атаку, не имея в арсенале доступ ни к одной доменной УЗ?
-
Kerberoasting (в т.ч. без пароля пользователя) + артефакты
🔥Атака Kerberoasting позволяет злоумышленнику захватить сервисную УЗ путём запроса TGS с указанием имени этой сервисной УЗ и последующим брутфорсом билета. А можно ли как-то провести атаку, не имея в арсенале доступ ни к одной доменной УЗ?
-
Microsoft’s guidance to help mitigate Kerberoasting: https://www.microsoft.com/en-us/security/blog/2024/10/11/microsofts-guidance-to-help-mitigate-kerberoasting/
-
Microsoft’s guidance to help mitigate Kerberoasting: https://www.microsoft.com/en-us/security/blog/2024/10/11/microsofts-guidance-to-help-mitigate-kerberoasting/
-
From last week's ADMIN Update newsletter: @cj_berlin takes a close look at a method known as Kerberoasting, an exploitation technique of the Kerberos authentication protocol.
https://www.admin-magazine.com/Archive/2024/81/Making-Kerberoasting-uneconomical
#cyberattack #Kerberoasting #authentication #security #Kerberos #ActiveDirectory -
From last week's ADMIN Update newsletter: @cj_berlin takes a close look at a method known as Kerberoasting, an exploitation technique of the Kerberos authentication protocol.
https://www.admin-magazine.com/Archive/2024/81/Making-Kerberoasting-uneconomical
#cyberattack #Kerberoasting #authentication #security #Kerberos #ActiveDirectory -
From last week's ADMIN Update newsletter: @cj_berlin takes a close look at a method known as Kerberoasting, an exploitation technique of the Kerberos authentication protocol.
https://www.admin-magazine.com/Archive/2024/81/Making-Kerberoasting-uneconomical
#cyberattack #Kerberoasting #authentication #security #Kerberos #ActiveDirectory -
From last week's ADMIN Update newsletter: @cj_berlin takes a close look at a method known as Kerberoasting, an exploitation technique of the Kerberos authentication protocol.
https://www.admin-magazine.com/Archive/2024/81/Making-Kerberoasting-uneconomical
#cyberattack #Kerberoasting #authentication #security #Kerberos #ActiveDirectory -
From last week's ADMIN Update newsletter: @cj_berlin takes a close look at a method known as Kerberoasting, an exploitation technique of the Kerberos authentication protocol.
https://www.admin-magazine.com/Archive/2024/81/Making-Kerberoasting-uneconomical
#cyberattack #Kerberoasting #authentication #security #Kerberos #ActiveDirectory -
Атака Kerberoasting без пароля пользователя — миф, или новая реальность?
Всем привет! Меня зовут Алексей, я работаю в компании «Визум», и занимаюсь тестированием на проникновение, направления классические – инфраструктура и веб. Данную статью меня сподвиг написать мой друг и коллега – Михаил Л., совместно с которым мы и провели данный небольшой ресерч. Все, кто, так или иначе, касался проведения атак на доменную инфраструктуру, построенную на основе Active Directory, почти 100% имели дело с атакой Kerberoasting, которая позволяет получить TGS-билеты для SPN, ассоциируемых с пользовательскими учетными записями, и далее - попробовать восстановить их пароли, при условии, что сами пароли достаточно простые (подробнее про атаку – прочитать можно тут ). Относительно недавно на Hack The Box появилась машина уровня INSANE – Rebound. Не буду расписывать, как ее решать, тем более – уже вышел официальный райтап от Ральфа . Хочу только обратить внимание на один момент из данного райтапа, а именно – проведение атаки Kerberoasing от имени доменного пользователя, к которому НЕТ пароля, но при этом - для пользователя не требуется прохождение Pre-Authentication (очень подробно про керберос можно почитать тут ).
-
Атака Kerberoasting без пароля пользователя — миф, или новая реальность?
Всем привет! Меня зовут Алексей, я работаю в компании «Визум», и занимаюсь тестированием на проникновение, направления классические – инфраструктура и веб. Данную статью меня сподвиг написать мой друг и коллега – Михаил Л., совместно с которым мы и провели данный небольшой ресерч. Все, кто, так или иначе, касался проведения атак на доменную инфраструктуру, построенную на основе Active Directory, почти 100% имели дело с атакой Kerberoasting, которая позволяет получить TGS-билеты для SPN, ассоциируемых с пользовательскими учетными записями, и далее - попробовать восстановить их пароли, при условии, что сами пароли достаточно простые (подробнее про атаку – прочитать можно тут ). Относительно недавно на Hack The Box появилась машина уровня INSANE – Rebound. Не буду расписывать, как ее решать, тем более – уже вышел официальный райтап от Ральфа . Хочу только обратить внимание на один момент из данного райтапа, а именно – проведение атаки Kerberoasing от имени доменного пользователя, к которому НЕТ пароля, но при этом - для пользователя не требуется прохождение Pre-Authentication (очень подробно про керберос можно почитать тут ).
-
Kerberoasting attacks explained (and how to prevent them) – Source: www.cybertalk.org https://ciso2ciso.com/kerberoasting-attacks-explained-and-how-to-prevent-them-source-www-cybertalk-org/ #rssfeedpostgeneratorecho #Kerberoastingattacks #Kerberoastingattack #CyberSecurityNews #ActiveDirectory #NetworkSecurity #Kerberoasting #TRENDINGNOW #Encryption #CyberTalk #passwords
-
Kerberoasting attacks explained (and how to prevent them) – Source: www.cybertalk.org https://ciso2ciso.com/kerberoasting-attacks-explained-and-how-to-prevent-them-source-www-cybertalk-org/ #rssfeedpostgeneratorecho #Kerberoastingattacks #Kerberoastingattack #CyberSecurityNews #ActiveDirectory #NetworkSecurity #Kerberoasting #TRENDINGNOW #Encryption #CyberTalk #passwords