Breach, Please!

Kerberoasting: Attack, Mitigation, and Detection


Listen Later

This episode is a discussion on Kerberoasting, a credential harvesting attack exploiting weak service account passwords within the Kerberos authentication system. The presentation details attack methods, both manual and automated, using tools like Mimikatz and Rubeus. It also covers mitigation strategies, including strengthening passwords and encryption, and detection techniques focusing on process creation, command lines, and event logs. Finally, it cites real-world examples of Kerberoasting's use by various threat actors.

...more
View all episodesView all episodes
Download on the App Store

Breach, Please!By Callie Guenther, Senior Manager - Cyber Threat Research at Critical Start