Threat actors are increasingly abusing overlooked Active Directory service principal name (SPN) misconfigurations to launch stealthier Kerberoasting attacks, turning ordinary user accounts into high-value credential targets. The technique, dubbed “Ghost SPN” by Trellix researchers, can allow an intruder with delegated directory permissions to temporarily assign an SPN to a standard account, request a Kerberos service […]
Read the original article: