Last updated
Last updated
If an account has SPN (Service Principal Name) set. We can request that account hash and try to crack it locally
For kerberos to work, times have to be within 5 minutes between attacker and victim.
There are many ways to do it.
Listing cached tickets
This powershell script is always my go to. It works pretty fine