Area 02 / 12
Kerberos & Authentication
Kerberos is the front door of the domain, and its weak defaults — RC4 tickets, accounts without pre-authentication, a krbtgt key that never changes — are what make Kerberoasting, AS-REP roasting and golden tickets practical. This area moves the realm to AES, rotates krbtgt safely and enables armoring.
Start the pathLearning path
0/4 done- 01Kerberos hardening: RC4, roasting and golden ticketsEnforce AES-only Kerberos, disable RC4 and DONT_REQ_PREAUTH, rotate krbtgt correctly, and detect Kerberoasting and golden ticket abuse.
- 02Disable RC4 in Kerberos: audit, fix and enforce AESRemove RC4 from Kerberos safely: audit 4768/4769, fix accounts without AES keys, set msDS-SupportedEncryptionTypes and DefaultDomainSupportedEncTypes, enforce.
- 03Rotating the krbtgt password safely in Active DirectoryRotate krbtgt without an outage: New-KrbtgtKeys.ps1, replication checks, RODC krbtgt accounts, a routine schedule and the incident-mode double reset.
- 04Defending against Kerberoasting and AS-REP roastingShrink Kerberoasting and AS-REP roasting exposure: inventory SPNs, remove stale ones, move to gMSA and AES, deploy a honey SPN and detect RC4 4769 spikes.