Take a Product Tour Request a Demo Cybersecurity Assessment Contact Us

Blogs

The latest cybersecurity trends, best practices, security vulnerabilities, and more

The Invisible Office Break-In: Understanding Kerberoasting Attacks and SPN Exploits

Imagine a massive corporate office building where every employee has a standard ID badge, but certain special "service accounts" (like the IT department or the maintenance crew) have a special VIP label (called an SPN) attached to their name.

Security guards closely monitor anyone trying to interact with those VIP accounts. But what if a regular employee's account accidentally gets assigned one of those VIP labels? Security ignores them because they look like an ordinary worker, but hackers can use that oversight to sneak past the front desk, steal digital keys, and take over the company network without triggering any alarms.

This blog explains exactly how hackers pull off this sneaky trick and how modern security tools catch them in the act.

What is "Kerberoasting"?

Think of Kerberoasting as a digital ticket scam. In a corporate network, computers don’t use passwords for everything; instead, they use digital "tickets" to grant access to different systems.

Here is how a standard Kerberoasting attack works:

  1. The request: Any regular employee can legally ask the system for a login ticket to access a company service.
  2. The catch: The system hands over a ticket that is locked (encrypted) using the password of that service.
  3. The theft: The hacker steals this ticket, takes it home, and uses a powerful computer to guess the password over and over again (offline brute-forcing). Because they are doing this on their own computer and not the company network, the target account never gets locked out from "too many wrong password attempts."

The new twist: The sneaky regular user trick

Normally, security teams only check the VIP accounts for this kind of behavior. Hackers figured this out, so they changed their strategy:

  • Finding the blind spot: Hackers look for ordinary, regular user accounts that were accidentally given a VIP label (an SPN).
  • Creating a trap: If they can't find one, hackers will hack a low-level account, use it to manually stick a VIP label onto another normal user, and disguise it to look totally legitimate.
  • Going unnoticed: Because security teams aren't looking at normal users for this kind of threat, the hacker can steal the login ticket completely undetected.

Step-by-step: How the Kerberoasting attack happens

When an attacker pulls this off, they follow a predictable script:

  • Step 1: Search: The hacker runs a script to find any account with a VIP label.
  • Step 2: Ask: They ask the network for a service ticket / TGS ticket for that account. The network blindly hands it over, using a weak, old-school type of digital lock that is incredibly easy to break.
  • Step 3: Steal: The hacker pulls the digital ticket out of the computer's temporary memory and saves it as a file.
  • Step 4: Use: Instead of even bothering to guess the password, the hacker just injects that stolen ticket back into their own computer session. The network thinks they are the authorized user and lets them right in.
>Figure 1: Attack flow: Abusing SPNs on user accounts in
                  Active Directory
Figure 1: Attack flow: Abusing SPNs on user accounts in Active Directory

How advanced network defense systems stop Kerberoasting automatically

Catching this attack manually is like finding a needle in a haystack because everything looks like normal network traffic. That is where advanced network defense systems like Trellix NDR come in.

Instead of waiting for the hacker to crack the password, the defense software looks at the behavior of the network:

  • AI-powered catching: The system spots the hacker scanning the network for those VIP labels before they even manage to steal a ticket. An AI assistant instantly maps out exactly what the hacker is trying to do.
  • Instant quarantine (hyperautomation): The security system can automatically disconnect the hacked computer from the internet and the rest of the company network with a single click—no manual coding required. Once the threat is cleaned up, it safely hooks the computer back up to the network.

Summary of recommendations

To prevent this sneaky attack, companies should:

  • Clean up the labels: Regularly check to make sure normal users don't have VIP labels (SPNs) attached to them.
  • Upgrade the locks: Stop using weak, outdated encryption methods for digital tickets.
  • Watch the network: Use smart monitoring tools that can spot hackers looking for these loopholes before they can exploit them.

To see how Trellix NDR can help protect your Active Directory, request a demo.

Get the latest

Stay up to date with the latest cybersecurity trends, best practices, security vulnerabilities, and so much more.
Please enter a valid email address.

Zero spam. Unsubscribe at any time.