Key Components of Kerberoasting
To understand the Kerberoasting attack, we need to understand how Kerberos itself works. Let’s look at some important components involved with Kerberos as it applies to Kerberoasting:
Ticket-granting Ticket (TGT) - When a user logs into a Windows system, they get a Ticket-granting Ticket (TGT) from the Key Distribution Center (KDC), a part of Active Directory.
Service Tickets - The TGT can be used to request service tickets for specific resources, like servers or services in the network.
Service Accounts - are often targeted because they are accounts associated with services running in the background. They have privileged access, many times they are members of the Domain Admin group. The passwords don’t get changed ...