T1558.003sub-technique of T1558 Steal or Forge Kerberos Tickets

Kerberoasting

Windows3 pieces on this siteT1558.003 on attack.mitre.org

Adversaries may abuse a valid Kerberos ticket-granting ticket (TGT) or sniff network traffic to obtain a ticket-granting service (TGS) ticket that may be vulnerable to Brute Force. Service principal names (SPNs) are used to uniquely identify each instance of a Windows service. To enable authentication, Kerberos requires that SPNs be associated with at least one service logon account (an account specifically tasked with running a service).

MITRE ATT&CK 19.2, retrieved 2026-09-12

If this is happening now

1

Checklists and playbooks to open while the alert is still live.

Playbook for this stage

Cloud account compromise

Impossible travel, an unrecognised inbox rule, or a reported invoice-fraud attempt.

Practise it

2

Labs, timelines, evidence packs and tabletop scenarios to work before you need to.

Guided labCONSTRUCTED

Guided lab: six service tickets in four seconds

A burst of Kerberos service ticket requests from one workstation, every one of them legitimate as far as the domain controller is concerned. Find what makes the cluster abnormal, separate it from a legacy application, and say what the log cannot tell you.

T1558.003

Read

1

Analyses, case studies, guides, references and interview questions.

ReferenceCONSTRUCTED

Windows event log cheat sheet: by the question you are asking

Organised by what you are trying to establish rather than by number: who logged on and how, what ran, what persisted, what was tampered with. Every entry says which log, whether it is on by default, and what it does not tell you.

T1558.003

how MITRE says to see it

Detect Kerberoasting Attempts (T1558.003)

  • Detects Kerberoasting attempts by monitoring for anomalous Kerberos TGS requests (Event ID 4769) with RC4 encryption (etype 0x17), accounts requesting an unusual number of service tickets in a short period, or service accounts targeted outside normal usage baselines.

what reduces it

  • M1027 Password Policies. Ensure strong password length (ideally 25+ characters) and complexity for service accounts and that these passwords periodically expire. Also consider using Group Managed Service Accounts or another third party product such as password vaulting.
  • M1026 Privileged Account Management. Limit service accounts to minimal required privileges, including membership in privileged groups such as Domain Administrators.
  • M1041 Encrypt Sensitive Information. Enable AES Kerberos encryption (or another stronger encryption algorithm), rather than RC4, where possible.

the rest of T1558

The description, detection analytics and mitigations are reproduced from MITRE ATT&CK, version 19.2, under its terms of use. The checklists, hunts, labs and everything else linked here are this site’s.