Cyberlium

Penetration › Module 7 › Lesson 3

BeginnerModule 7Lesson 3/5

Auth Abuse Named

Kerberoasting and Pass-the-Hash named as concepts — defender focus and $LAB_AD literacy, not stranger-domain cookbooks.

15 min+40 XP3 quiz
Module progress3 of 5

Visual · t19_auth_abuse_named

Auth abuse = misuse of Kerberos/NTLM mechanisms. Named only on $LAB_AD. Original Cyberlium.

Opening

Know what Kerberoast and PtH mean so you can detect them — not so you can run them on a domain you do not own.

Authentication abuse concepts defenders must know: Kerberoasting (requesting service tickets for SPN accounts to offline crack weak passwords — T1558.003), Pass-the-Hash (reusing NTLM hashes without plaintext — T1550.002), Pass-the-Ticket, AS-REP roasting (weak preauth), and password spraying (controlled rate — refused outside RoE). Cyberlium names these for blue-team literacy and authorized $LAB_AD exercises per brief — NOT full attack cookbooks for stranger domains, NOT spraying real university or employer AD, NOT sharing cracked hashes publicly. Defenders mitigate with strong service account passwords, AES-only Kerberos where possible, LAPS, tiered admin, and detection on ticket anomalies.

1. Kerberoasting (concept)

Attacker requests TGS for SPN-linked account; offline crack if password weak — service accounts are high risk.

Defender: long random service passwords, managed service accounts, monitor anomalous TGS requests.

Command guide

Try these commands — Kerberoasting (concept)

═══ TOOLS & WEBSITES ═══ Browse / read these (authorized learning only — stay in YOUR lab / program scope)

MITRE ATT&CK — https://attack.mitre.org/ (technique pages for literacy) AD notes — lab domain only

═══ INSTALL ═══

Linux (Debian/Ubuntu):

Command — copy this

sudo apt install curl

macOS: Built-in

Windows: Built-in (PowerShell: Invoke-WebRequest)

═══ LINUX / macOS ═══

Command — copy this

curl -sS https://attack.mitre.org/tactics/TA0006/ | head -8
grep lab_ad "$HOME/cyberlium-lab/t19-ad-notes.txt" 2>/dev/null || echo 'lab_ad: YOUR AD lab only'

Primary tools to practice this lesson: curl, grep. Reference sites: MITRE ATT&CK (https://attack.mitre.org/); AD notes. Run every command in the box — install first, then the usage lines — only on YOUR lab / program scope.

2. Pass-the-Hash (concept)

NTLM hash reuse to authenticate without plaintext — lateral movement category on lab only under RoE.

Defender: Credential Guard, restrict NTLM, Protected Users group, monitor unusual logon types.

3. Hard refusal

No Kerberoast/PtH/spray against stranger domains, production employer AD, or internet-exposed DCs.

Lab exercises use disposable $LAB_AD accounts with known-weak passwords per brief — then revert snapshot.

4. What you ship: auth abuse literacy card

Kerberoast + PtH one-liners + ATT&CK IDs + three defender mitigations + NEVER stranger AD.

5. What you record before the next lesson

Auth abuse literacy card path.

6. Wrong vs right: stranger nets vs YOUR lab VMs

Worked failure — same MSF word, opposite target. Right never needs a café Wi-Fi or classmate laptop.

  • Wrong

    Kerberoast a production SaaS company's AD because a blog post showed commands.

  • Right

    Name auth abuse concepts and defenses. Next: AD Lab.

Mission: auth abuse literacy card

1) Define Kerberoasting and Pass-the-Hash in one line each. 2) Name ATT&CK IDs if brief provides. 3) List three defender mitigations. 4) Write NEVER stranger-domain auth abuse.

Stuck? Ask Cyberlium AI Mentor

Ask Mentor: “Protected Users group — what it blocks?”

Knowledge Check

1

APPLY: Kerberoasting targets:

Multiple choice

Knowledge Check

2

APPLY: True or False: Pass-the-Hash on stranger AD is course lab.

True or False

Knowledge Check

3

APPLY: Defenders mitigate PtH with:

Multiple choice

← Previous

Answer all 3 knowledge checks to continue. (0/3 answered)