Glossary
Kerberoasting
Kerberoasting is an attack that extracts service account password hashes from Kerberos service tickets for offline cracking.
Kerberoasting targets Active Directory accounts that have a Service Principal Name (SPN) registered. Any authenticated domain user can request a Kerberos service ticket for such an account, and part of that ticket is encrypted with the service account's password hash. Because that encryption can be attacked offline, without generating further traffic against the domain controller, an attacker with low-privilege domain access can harvest tickets for many service accounts at once and attempt to recover their plaintext passwords at leisure.
This matters because service accounts are frequently over-privileged and configured with passwords that are old, never rotated, or manually chosen rather than randomly generated. A successful crack can hand an attacker a high-privilege credential without ever touching the DC's authentication logs suspiciously. Mitigation centers on strong, long, randomly generated service account passwords (ideally via gMSA), avoiding unnecessary SPNs, and using AES-only Kerberos encryption alongside ticket-request monitoring.
See Kerberos hardening.