Back Issues/Search Home → Calendar → Archive → Current Issue → Popular →

All issuesVolume 341, Issue 4IT Vendor NewsTrellix

No Privileges, No Lockout, No Trace: Kerberoasting With SPN Misconfigurations

Trellix, Thursday, August 27th, 2026

Trellix details a stealthy Kerberoasting variant abusing service principal names assigned to ordinary user accounts.

Trellix researchers Maulik Maheta and Henry Bernabe document a stealthier evolution of Kerberoasting that weaponizes a common Active Directory oversight: service principal names assigned to ordinary user accounts rather than dedicated service accounts.

Because security teams typically audit service accounts for SPNs and not standard users, the misconfiguration creates a detection blind spot.

The blog walks through the complete kill chain, in which an attacker enumerates domain-wide SPNs, identifies a vulnerable user account, and silently requests a Kerberos Ticket Granting Service ticket encrypted with the weak RC4-HMAC algorithm for offline cracking.

The attack requires no elevated privileges, triggers no account lockout and leaves little trace.

more →  ·  More from Trellix →