A SOC analyst reviews SIEM logs and notices a sudden spike in Kerberos TGS-REQ packets originating from a single workstation, targeting multiple Service Principal Names (SPNs) across the domain. The tickets are encrypted with RC4-HMAC. The workstation’s EDR shows no process injection or lateral movement. What is the most likely indicator of malicious activity in this scenario?
Select an answer to reveal the explanation.
Short Explanation
Think of Kerberoasting like asking for a bunch of locked boxes (tickets) from different departments (SPNs) to see if you can pick the locks at home. You don't need to hack the server; you just ask for the ticket, which is encrypted with the service account's password. If you see a flood of TGS-REQs for SPNs, especially with weak encryption like RC4, that's your red flag. Don't get distracted by latency or maintenance; focus on the pattern of requests.
Full Explanation
Kerberoasting exploits the way Kerberos handles service authentication. When a client requests a Service Ticket (TGS) for a Service Principal Name (SPN), the Key Distribution Center (KDC) encrypts the ticket using the service account’s password hash. The client then sends this ticket to the service. An attacker can request these tickets for many SPNs and then crack them offline because the service does not need to interact with the KDC to validate the request. The use of RC4-HMAC is a critical indicator because it is a legacy encryption type susceptible to offline brute-force attacks, unlike newer AES-based types. This scenario tests the analyst's ability to distinguish between normal authentication noise and targeted harvesting. A benign service account check would typically involve a small number of SPNs and not a sudden spike from a user workstation. Kerberos armoring (FAST) is a protection mechanism that wraps tickets in a secure channel; its misconfiguration would not generate this specific pattern of unarmored TGS-REQs. DNS latency might cause retries, but it would not result in a systematic request for multiple distinct SPNs from a single source. Exam caveat: Always correlate the encryption type with the volume of requests; RC4 + high volume = high risk. Operational check: Verify if the source workstation has a legitimate business reason to authenticate to the specific SPNs requested and check if Kerberos armoring is enforced in the domain policy.