Kerberos Configuration on User Account

medium

Description

Active Directory relies on Kerberos for authentication. It is an older protocol that has since received various security hardening measures. For this reason, it's necessary to disable some legacy options (e.g. the obsolete "DES" encryption or "Do not require Kerberos preauthentication") to ensure proper security such as avoiding "AS-REP Roasting" attacks.

Solution

To ensure the highest level of security, configure the Active Directory's authentication protocol to use the latest security parameters and protocols.

See Also

What Is Kerberos Authentication?

Kerberos RFC 4120

Authentication secrets part II - Kerberos strikes-back

Kerberos Protocol Tutorial

Indicator Details

Name: Kerberos Configuration on User Account

Codename: C-KERBEROS-CONFIG-ACCOUNT

Severity: Medium

MITRE ATT&CK Information:

Attacker Known Tools

HarmJ0y, Elad Shamir: Rubeus