CTD-000058

Privileged AD user account with associated SPNs

High
Active Directory
Credential Access Lateral Movement
v30

Signature Identity

CTD-000058
Threat ID
30
Version
IOE
Indicator Type

Threat Description

Kerberoasting attacks abuse the Kerberos Ticket Granting Service (TGS) to gain access to accounts, typically targeting domain accounts for lateral movement.
Kerberoasting attacks involve scanning an Active Directory environment to generate a list of user accounts that have Kerberos Service Principal Name (SPN). Attackers then request these SPN to grant Kerberos Service Tickets to these accounts. The tickets are dumped from memory using various tools like Mimikatz and then exfiltrated for offline brute forcing on the encrypted segment of the tickets. If successful, attackers can identify the passwords associated with the accounts, which they then use to remotely sign into machines or access resources.
To reduce the impact of possible kerberoasting attacks make sure that service accounts do not have administrative privileges.

NOTE: Cayosoft Guardian defines privileged users in Active Directory as users with adminCount=1. By design Active Directory uses this attribute to protect members of administrative groups.

According to security best practices it is not recommended re-using admin accounts, instead these accounts must be de-provisioned. If an account has administrative permissions, it might also obtain access to other resources using these administrative permissions and keep this access even after it is removed from the administrative groups. Learn more about AdminSdHolder and SDProp – Microsoft Community Hub.

MITRE ATT&CK: Attack Tactics

Credential Access Lateral Movement

D3FEND: Defend Tactics

Application Configuration Hardening Domain Account Monitoring User Account Permissions

Remediation

To mitigate risk of successful decoding of the password of a service account with kerberoasting attack regularly change password of the associated service accounts using password longer than 28 characters.
To reset a password of a user account:
  1. Click Start.
  2. Point to Control Panel.
  3. Point to Administrative Tools.
  4. Click Active Directory Users and Computers.
  5. Find the user account whose password you want to reset.
  6. In the right pane, right-click on the user account and select Reset password.
  7. Type the new password and enter it again to confirm.

Frequently Asked Questions

What does Privileged AD user account with associated SPNs mean?

A Privileged AD user account is an Active Directory user account granted administrative privileges. When associated with Service Principal Names (SPNs), it enables the account to access sensitive resources and perform administrative tasks, making it a high-risk target for attackers.

This combination of elevated privileges and Kerberos Service Ticket capabilities allows an attacker who gains access to request tickets for lateral movement and credential access, enabling them to move undetected within the domain and access sensitive resources. Specifically, this enables the exploitation of Kerberos protocol vulnerabilities, such as Golden Ticket attacks.

Attackers exploit the account's Kerberos Service Ticket capabilities by requesting tickets that grant access to sensitive resources, allowing for lateral movement and credential access without being detected. This enables them to escalate privileges, move laterally within the domain, and access sensitive data.

Cayosoft Guardian continuously monitors Active Directory for accounts with administrative privileges and associated SPNs, flagging them as security issues so administrators can remediate the risk promptly.

Cayosoft Guardian alerts administrators to review and remediate the issue, supporting ongoing monitoring to detect any changes to the privileged account's status or configuration. This helps prevent attackers from exploiting the account for lateral movement and credential access.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Active Directory
Themes
Account protection
Attack Tactics
Credential Access Lateral Movement
Defend Tactics
Application Configuration Hardening Domain Account Monitoring User Account Permissions
Indicator Types
IOE
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical