No Privileges, No Lockout, No Trace: Kerberoasting With SPN Misconfigurations
Trellix, Thursday, August 27th, 2026
Trellix details a stealthy Kerberoasting variant abusing service principal names assigned to ordinary user accounts.
Trellix researchers Maulik Maheta and Henry Bernabe document a stealthier evolution of Kerberoasting that weaponizes a common Active Directory oversight: service principal names assigned to ordinary user accounts rather than dedicated service accounts.
Because security teams typically audit service accounts for SPNs and not standard users, the misconfiguration creates a detection blind spot.
The blog walks through the complete kill chain, in which an attacker enumerates domain-wide SPNs, identifies a vulnerable user account, and silently requests a Kerberos Ticket Granting Service ticket encrypted with the weak RC4-HMAC algorithm for offline cracking.
The attack requires no elevated privileges, triggers no account lockout and leaves little trace.