Kerberos

Kerberos is the primary authentication protocol in Active Directory, and almost every high-value AD attack ends up in Kerberos terms. Its design gives an attacker several distinct openings: the encrypted parts of tickets are derived from an account's key, so they can be roasted and cracked offline; the key itself authenticates, so it can be reused without the password; and whoever holds the krbtgt key or a service key can forge tickets at will.

How the openings arise#

A quick model of the protocol explains each attack:

  • The client proves its identity to the KDC (AS exchange) and receives a TGT encrypted with the krbtgt key.
  • It presents the TGT to get service tickets (TGS exchange), each encrypted with the target service account's key.
  • The service trusts the ticket because it can decrypt it with its own key, and trusts the privileges inside (the PAC) because the KDC signed them.

Every trust in that chain is a target: the account key (roasting, pass-the-key), the TGT (pass-the-ticket, golden ticket), the service key (silver ticket), the PAC (diamond/sapphire tickets), and the delegation flags that let one service request tickets as another user.

Pages#

References#

  • The Hacker Recipes: Kerberos
  • Microsoft: Kerberos authentication and the PAC

Cookie Consent

We use cookies to enhance your experience. Learn more