For the complete documentation index, see llms.txt. This page is also available as Markdown.

Possible Kerberoasting without SPNs

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

Requires one of the following data sources: Palo Alto Networks Firewall traffic Logs OR XDR Agent

ATT&CK Tactic

Credential Access (TA0006)

ATT&CK Technique

Steal or Forge Kerberos Tickets: Kerberoasting (T1558.003)

Severity

Low

Description

A user specifically requested weak and deprecated encryption in a Kerberos TGS request. This provides easy-to-crack hashes, and is typically a sign of a Kerberoasting attack. The requested service was specified by using a suspicious SPN type, which is often used by Kerberoasting tools to request by SAN instead of SPN.

Attacker's Goals

Crack service account credentials by obtaining an easy-to-crack Kerberos ticket.

Investigative actions

Check who used the host at the time of the alert to rule out a benign service or tool requesting weak Kerberos encryption.

Variations

Possible Kerberoasting without SPNs on a sensitive server

Synopsis

Field
Value

ATT&CK Tactic

Credential Access (TA0006)

ATT&CK Technique

Steal or Forge Kerberos Tickets: Kerberoasting (T1558.003)

Severity

Medium

Description

A user specifically requested weak and deprecated encryption in a Kerberos TGS request. This provides easy-to-crack hashes, and is typically a sign of a Kerberoasting attack. The requested service was specified by using a suspicious SPN type, which is often used by Kerberoasting tools to request by SAN instead of SPN.

Attacker's Goals

Crack service account credentials by obtaining an easy-to-crack Kerberos ticket.

Investigative actions

Check who used the host at the time of the alert to rule out a benign service or tool requesting weak Kerberos encryption.

Was this helpful?