Detecting Kerberoasting with PowerShell and logs
November 14, 2025
Detecting Kerberoasting with PowerShell and Logs
Kerberoasting is an Active Directory attack technique where an attacker requests Kerberos service tickets (TGS)
for accounts that have Service Principal Names (SPNs), then cracks the ticket offline to recover the service
account password. Because it uses legitimate Kerberos flows, the key to detection is understanding what…


