kerberoasting
introduction
- get a TGS, need a valid domain user account
- get TGT from domain controller
- try to get a authentication hash
- try to crack that
walkthrough
Add serviceprincipalname to a user that we have genericall upon
With PowerView.ps1:
migitation
- strong passwords
- least privilege
references