Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Kerberoasting is an Active Directory attack in which an attacker requests Kerberos service tickets for accounts linked to service principal names (SPNs), then tries to crack the ticket material offline to recover the service account password. Because password guesses are tested against the captured ticket rather than submitted as repeated logins to a domain controller, the activity may not produce a stream of failed-password events. The risk depends on the password’s strength and the account’s privileges.
How a Kerberoasting attack works
In Active Directory, an SPN identifies a service instance and is associated with the account that runs the service. Kerberos issues a service ticket for that account when a client requests access. An attacker who can request tickets can obtain encrypted ticket material and attempt password guesses against it offline.
| # | Preview | Product | Price | |
|---|---|---|---|---|
| 1 |
|
Network Security, Firewalls, and VPNs | $66.62 | Buy on Amazon |
| 2 |
|
Network Security, Firewalls, and VPNs: . (Issa) | $62.45 | Buy on Amazon |
| 3 |
|
TP-Link ER605, Wired Gigabit VPN Router | $44.99 | Buy on Amazon |
| 4 |
|
Cybersecurity for Small Networks: A Guide for the Reasonably Paranoid | $33.89 | Buy on Amazon |
- Find service accounts and SPNs. The attacker identifies accounts associated with network services.
- Request service tickets. The attacker asks the domain for Kerberos tickets for those services. MITRE ATT&CK describes this as abuse of normal Kerberos ticket-request functionality.
- Extract and crack ticket material. The attacker takes the encrypted material offline and tests password guesses without making each guess a live domain login.
- Use any recovered credentials. If a password is cracked, the attacker can act as that service account, subject to its permissions and access.
This differs from password spraying or brute-force login attempts: Kerberoasting targets service tickets associated with SPNs, and the password guessing happens offline. MITRE ATT&CK’s Kerberoasting technique entry explains the technique and its defensive considerations.
What defenders should look for
Event ID 4769 records Kerberos service-ticket requests on Windows domain controllers. MITRE recommends looking for unusual request volume over a short period, requests for service accounts outside their normal patterns, and tickets using RC4 encryption, identified as etype 0x17. These are indicators for investigation, not proof: legitimate systems may still depend on RC4, so establish a local baseline before treating an alert as malicious.
#1 Best Overall
- Compare each account’s ticket-request volume and timing with its ordinary use.
- Investigate requests for services or service accounts that are unusual for the requesting user, device, or environment.
- Review RC4 use alongside the request pattern and account context rather than treating the encryption type alone as conclusive.
Microsoft’s classic Microsoft Defender for Identity alerts documentation describes a related sequence—SPN and service-account enumeration, ticket requests, ticket or hash extraction, and offline cracking—which may provide another monitoring route for organizations using the product.
How to reduce Kerberoasting risk
Prefer AES after checking compatibility
Where supported, use AES Kerberos encryption rather than RC4. First audit which accounts, clients, and services still rely on RC4; changing encryption settings without checking legacy dependencies can disrupt authentication. Microsoft’s RC4 detection and remediation guidance covers auditing events 4768 and 4769 on supported Windows domain controllers. The behavior and event details available depend on Windows Server version and cumulative updates. MITRE’s Encrypt Sensitive Information mitigation also recommends stronger encryption where possible.
Rank #2
- Available with the Cloud Labs which provide a hands-on, immersive mock IT infrastructure enabling students to test their skills with realistic security scenarios
- New Chapter on detailing network topologies
- The Table of Contents has been fully restructured to offer a more logical sequencing of subject matter
- Introduces the basics of network security—exploring the details of firewall security and how VPNs operate
- Increased coverage on device implantation and configuration
Use managed service accounts where feasible
Group managed service accounts (gMSAs) can reduce the burden of manually managing service-account passwords when the workload supports them. For workloads that cannot use gMSAs, use a long, unique, unpredictable password and rotate it through a controlled process. CISA and partner agencies recommend a minimum 30-character password for certain service-account cases where gMSAs are not feasible, including some non-Windows services or applications without full gMSA support. This is guidance for those cases, not a universal password rule.
Limit service-account permissions
Grant each service account only the access its service needs. Avoid unnecessary privileged-group membership: if an account is compromised, excessive permissions can increase the impact.
Rank #3
- 【Five Gigabit Ports】1 Gigabit WAN Port plus 2 Gigabit WAN/LAN Ports plus 2 Gigabit LAN Port. Up to 3 WAN ports optimize bandwidth usage through one device.
- 【One USB WAN Port】Mobile broadband via 4G/3G modem is supported for WAN backup by connecting to the USB port. For complete list of compatible 4G/3G modems, please visit TP-Link website.
- 【Abundant Security Features】Advanced firewall policies, DoS defense, IP/MAC/URL filtering, speed test and more security functions protect your network and data.
- 【Highly Secure VPN】Supports up to 20× LAN-to-LAN IPsec, 16× OpenVPN, 16× L2TP, and 16× PPTP VPN connections.
- Security - SPI Firewall, VPN Pass through, FTP/H.323/PPTP/SIP/IPsec ALG, DoS Defence, Ping of Death and Local Management. Standards and Protocols IEEE 802.3, 802.3u, 802.3ab, IEEE 802.3x, IEEE 802.1q
Monitor, investigate, and respond
Build a baseline for Event 4769, then investigate meaningful deviations, including unusual request bursts, atypical targets, or unexpected RC4 use. If compromise is suspected, investigate the account’s activity and rotate its credentials as part of a controlled response.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Choosing the right defensive priorities
Prioritize controls based on how your environment actually uses Kerberos. The useful questions are whether services and clients support AES, whether workloads can use gMSAs, how service-account secrets are managed, what permissions those accounts hold, and whether existing logs let you distinguish normal from unusual ticket requests. Addressing password strength alone does not replace limiting privileges or monitoring ticket activity.
MITRE ATT&CK says service-account passwords should ideally be 25 or more characters. CISA and partner agencies’ 30-character recommendation applies to certain cases where gMSAs are infeasible. These are separate recommendations, not measured attack-prevalence figures.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Free tools Windows power users keep installed
One-click scans. No signup required.

