Your Network's Digital Doorman
To understand Kerberoasting, you first have to know about Kerberos. It's the default authentication protocol in nearly every corporate Windows network, acting like a digital doorman for your entire IT environment. Its job is to verify that users and services
are who they say they are. It does this by issuing encrypted 'tickets' that grant access without sending passwords across the network. Think of it as a trusted system that hands out temporary keycards. In this system, many applications and services (like databases or web servers) need their own identities to function. These are called 'service accounts.' They are non-human accounts with specific privileges, and they are the primary target of this attack.
How the Heist Unfolds
A Kerberoasting attack begins after a threat actor has already gained a foothold inside your network—even with a low-level, non-admin user account. From there, the attacker simply asks the Kerberos system for a service ticket (specifically, a Ticket-Granting Service or TGS ticket) for a specific service, like one for a SQL database. Because of how Kerberos is designed, any authenticated user can request a ticket for any service, and the system usually obliges without checking if that user is actually allowed to access it. This is a legitimate-looking request that won't set off alarms. The system hands over the ticket, which is encrypted with a key derived from the service account's own password. The attacker then takes this encrypted ticket and goes 'offline'—back to their own machine—to start cracking it.
The 'Hidden' Weak Link Isn't the Tech
Herein lies the hidden vulnerability: it’s not a flaw in the Kerberos protocol itself, but a problem of human oversight and poor IT hygiene. The real weakness is the password used for that service account. These accounts are often set up and forgotten. Their passwords might be simple, based on a predictable pattern, or worst of all, set to never expire. While your company may enforce strong password policies for employee user accounts, service accounts frequently slip through the cracks. Attackers know this. They use powerful hardware to run brute-force attacks on the stolen ticket offline, trying millions of password combinations per second. Since this cracking happens on their own computers, it’s invisible to your security tools. A weak password that might take centuries to crack online can be broken in mere hours or days offline.
From a Single Crack to Owning the Kingdom
Once the password is cracked, the attacker possesses the plaintext credentials of the service account. They can now log in and impersonate that service. Depending on how the account was configured, this could grant them immense power. Service accounts are often given high-level privileges to perform their duties—sometimes even domain administrator rights. With these credentials, the attacker can move laterally through the network, escalate their privileges further, access sensitive data, deploy ransomware, and establish persistent backdoors for future access. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has noted that Kerberoasting is one of the most efficient ways for an attacker to elevate privileges inside a network. The initial breach was quiet, and the devastating escalation happens under the guise of a legitimate account.
Bolting the Door the Right Way
Because Kerberoasting exploits normal behavior, it can't be 'patched' away. Mitigation is about making the attack too difficult to be worthwhile. The single most effective defense is enforcing incredibly strong passwords for all service accounts. Security experts recommend randomly generated passwords of 25 characters or more. Organizations should also use modern, stronger encryption standards like AES for Kerberos tickets, as older standards are much easier to crack. Auditing accounts to find and remove unnecessary service privileges is crucial, as is monitoring for unusual ticket requests. For more advanced protection, using Group Managed Service Accounts (gMSAs), which automatically manage and rotate complex passwords, removes the human element of forgetfulness and is a highly recommended practice.













