Active Directory SPN Misconfigurations Enable Kerberoasting Without Account Lockouts

A common configuration error in Active Directory is assigning Service Principal Names (SPNs) to ordinary user accounts. This mistake can create an overlooked path for Kerberoasting attacks, allowing adversaries to obtain credentials without needing privileged access or causing account lockouts. Kerberoasting typically targets Active Directory service accounts that hold SPNs, which Kerberos uses to identify […]

This article has been indexed from GBHackers Security | #1 Globally Trusted Cyber Security News Platform

Read the original article: