OWASP Kerberoasting
OWASP Kerberoasting
» Kerberos 101
» Kerberoasting
» Silver Tickets
» Golden Tickets
» Wrapping up
Agenda
» Kerberos 101
» Kerberoasting
» Silver Tickets
» Golden Tickets
» Wrapping up
Kerberos 101 - Overview
» Client (Principal)
» Server
» Kerberos Distribution Center
» Authentication Service
» Ticket Granting Service
» Kerberos 101
» Kerberoasting
» Silver Tickets
» Golden Tickets
» Wrapping up
Kerberoasting - Overview
» Kerberos 101
» Kerberoasting
» Silver Tickets
» Golden Tickets
» Wrapping up
Silver Tickets - Overview
» Indicators
» The Account Domain field is blank when it should be DOMAIN
» The Account Domain field is DOMAIN FQDN when it should be DOMAIN.
» Events:
» 4624 Account Logon
» 4634 Account Logoff
» 4672 Admin Logon
» Kerberos 101
» Kerberoasting
» Silver Tickets
» Golden Tickets
» Wrapping up
Golden Tickets - Overview
» Kerberos 101
» Kerberoasting
» Silver Tickets
» Golden Tickets
» Wrapping up
Wrappig Up
» https://leonjza.github.io/blog/2016/01/09/kerberos-kerberoast-and-golden-tickets/
» https://adsecurity.org/?p=1515
» https://adsecurity.org/?page_id=1821
» https://blogs.technet.microsoft.com/askds/2008/03/06/kerberos-for-the-busy-admin/
» https://www.roguelynn.com/words/explain-like-im-5-kerberos/
» https://www.varonis.com/blog/kerberos-attack-silver-ticket/
» https://www.varonis.com/blog/kerberos-how-to-stop-golden-tickets/
» https://www.sans.org/cyber-security-summit/archives/file/summit-archive-
1493862736.pdf
» https://blog.stealthbits.com/extracting-service-account-passwords-with-kerberoasting/
» https://room362.com/post/2016/kerberoast-pt1/
Tools
» Rubeus: https://github.com/GhostPack/Rubeus
» Powersploit: https://github.com/PowerShellMafia/PowerSploit
» Mimikatz: https://github.com/gentilkiwi/mimikatz
» Powershell Empire: https://github.com/EmpireProject/Empire