1200KM / simulation
T1558.003 Kerberoasting — Attack Simulation
Adversaries may abuse a valid Kerberos ticket-granting ticket (TGT) or sniff network traffic to obtain a ticket-granting service (TGS) ticket that may be vulnerable to Brute Force. Service principal names (SPNs) are used to uniquely identify each instance of a Windows service. To enable authentication, Kerberos requires that SPNs be associated with at least one service logon account (an account specifically tasked with running a service).…
Technique description
Adversaries may abuse a valid Kerberos ticket-granting ticket (TGT) or sniff network traffic to obtain a ticket-granting service (TGS) ticket that may be vulnerable to Brute Force. Service principal names (SPNs) are used to uniquely identify each instance of a Windows service. To enable authentication, Kerberos requires that SPNs be associated with at least one service logon account (an account specifically tasked with running a service).…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Rubeus kerberoast
Procedure 14625569-6def-4497-99ac-8e7817105b55; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- WinPwn - PowerSharpPack - Kerberoasting Using Rubeus
Procedure 29094950-2c96-4cbd-b5e4-f7c65079678f; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Request for service tickets
Procedure 3f987809-3681-43c8-bcd8-b3ff3a28533a; elevation not declared required; cleanup not declared. Not executed or individually validated.
- WinPwn - Kerberoasting
Procedure 78d10e20-c874-45f2-a9df-6fea0120ec27; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Request All Tickets via PowerShell
Procedure 902f4ed2-1aba-4133-90f2-cff6d299d6da; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Request A Single Ticket via PowerShell
Procedure 988539bc-2ed7-4e62-aec6-7c5cf6680863; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Extract all accounts in use as SPN using setspn
Procedure e6f4affd-d826-4871-9a62-6c9004b8fe06; elevation not declared required; cleanup not declared. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing research
Connected anomaly research
Curated research views reached through an exact source technique, a catalog model, or a reviewed collection reference. These are navigation associations, not claims of detector effectiveness or sensor equivalence.
Telemetry contracts · Maintained query examples · Validation and blind spots
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.