Kerberoasting
Extract TGS tickets for service accounts and crack offline.
AD centralizes identity and policy management across enterprise Windows environments using domains, users, groups, and organizational units.
Extract TGS tickets for service accounts and crack offline.
Reuse NTLM hash to authenticate without plaintext credentials.
Initial foothold -> local admin -> domain user token -> service account abuse -> domain controller access.