A penetration tester is targeting an Active Directory environment. They successfully compromise a low-privileged user account. The tester discovers that this user account has a Service Principal Name (SPN) registered. The tester wants to obtain the NTLM hash of the service account associated with this SPN for offline cracking. Which Active Directory attack method should the tester employ?
- ANTLM Relay Attack
- BPass-the-Hash
- CKerberoasting
- DGolden Ticket Attack
Show answer & explanationAnswer & explanation
Correct answer: C. Kerberoasting
Kerberoasting specifically targets service accounts that have an SPN registered. It exploits the Kerberos protocol by requesting a service ticket for the target SPN. The Key Distribution Center (KDC) encrypts this ticket with the NTLM hash of the service account. An attacker can then extract this encrypted ticket (TGS) and attempt to crack the NTLM hash offline, without needing to interact with the service itself.
Why the other options are wrong
- A. NTLM Relay attacks typically involve intercepting and relaying NTLM authentication, not requesting Kerberos service tickets for SPNs.
- B. Pass-the-Hash uses an already obtained NTLM hash to authenticate, it doesn't describe the method of obtaining the hash from an SPN.
- D. A Golden Ticket attack requires compromise of the KDC (krbtgt hash) to forge tickets, not just a service account SPN.
Kerberoasting
An Active Directory attack that exploits the Kerberos protocol to request service tickets (TGS) for service principal names (SPNs), which are encrypted with the NTLM hash of the associated service account. These tickets can then be extracted and cracked offline to recover the service account's password.
- Targets service accounts with SPNs.
- Does not require administrator privileges.
- Offline cracking of NTLM hashes.
- Can be detected by monitoring for excessive TGS requests.
Memory trick: Kerberoasting: SPNs reveal service secrets for cracking.