Kerberoasting - MITRE ATT&CK

Threat entity extracted from intelligence sources

Frequency
4
occurrences
First Seen
November 6, 2025
Last Seen
July 30, 2026

Kerberoasting is a credential-access technique in Kerberos-enabled environments where an attacker requests service tickets for service principal names (SPNs), extracts the encrypted portion of those tickets, and offline-brute-forces the ticket to recover the target service account password.

Overview

Kerberoasting is a credential-access technique in Kerberos-enabled environments where an attacker requests service tickets for service principal names (SPNs), extracts the encrypted portion of those tickets, and offline-brute-forces the ticket to recover the target service account password. This enables attackers to obtain domain credentials and escalate privileges with relatively low initial access, making it a significant risk in Windows Active Directory environments.

Related Threat Clusters

  • Gootloader Malware Resurgence Leads to Domain Controller Compromise

    Recent Gootloader attacks have resulted in a Domain Controller compromise within 17 hours, as reported by Huntress. The Gootloader malware, which has been active since 2020, was previously inactive but saw a resurgence…

    2 articles · Updated November 6, 2025
  • Gootloader Malware Resurfaces, Compromises Domain Controllers

    Gootloader malware has re-emerged after a period of reduced activity, with Huntress reporting three infections since October 27, 2025. Two of these incidents resulted in hands-on-keyboard intrusions, leading to domain…

    4 articles · Updated November 7, 2025
  • New Open Source Tools Enhance AI Defense Against Cyber Threats

    Dreadnode has launched two open-source tools, DreadGOAD and Ares, aimed at improving the effectiveness of AI in cybersecurity defense. DreadGOAD simulates complex Active Directory environments, while Ares evaluates red…

    2 articles · Updated July 29, 2026
  • Microsoft to Retire RC4 Cipher in Active Directory by 2026

    Microsoft is set to retire the RC4 cipher for administrative authentication in Active Directory by 2026. This decision addresses vulnerabilities that have been exploited in significant cyberattacks over the past decade.…

    3 articles · Updated December 17, 2025
  • Microsoft Initiates Removal of Insecure RC4 Encryption in Windows Update

    Microsoft's January Patchday updates address a security vulnerability in Kerberos authentication and mark the beginning of the phase-out of the insecure RC4 encryption method. The patch aims to enhance the security of…

    1 article · Updated January 19, 2026

Recent Intelligence Reports

  • Mine The Gap Open Source Tools For Measuring The Ai Offense Defense Gap — www.dreadnode.io · July 30, 2026
  • Microsoft starts with identification of insecure RC4 encryption — Heise.De · January 19, 2026
  • Beyond RC4 for Windows Authentication — News.Ycombinator · December 17, 2025
  • New Gootloader attacks drop Supper SOCKS5 backdoor — Scmagazine · November 6, 2025

CVSS v3.1 Breakdown