Ad - Kerberoasting Detect
Ad - Kerberoasting Detect
Techniques
Keywords: MS Active Directory, Kerberos Security, Kerberoasting, Cyber Security, Cyber Attacks.
Abstract: The paper focus is the detection of Kerberoasting attack in Active Directory environment. The purpose of the
attack is to extract service accounts’ passwords without need for any special user access rights or privilege
escalation, which makes it suitable for initial phases of network compromise and further pivot for more
interesting accounts. The main goal of the paper is to discuss the monitoring possibilities, setting up detection
rules built on top of native Active Directory auditing capabilities, including possible ways to minimize false
positive alerts.