Episode 75 - Why Kerberoasting is still everywhere in 2026
SHOW NOTES
What is Kerberoasting and why is it still wrecking enterprise networks? In this episode of SecOps Weekly, Red Siege CEO Tim Medin explains why Kerberoasting — an attack targeting the Kerberos authentication protocol in Windows Active Directory environments — remains a prevalent threat for SecOps teams more than a decade after he coined the term. The conversation covers how attackers exploit service tickets (TGS) to perform offline cracking of password hashes, particularly when weak RC4 encryption is used.
TIMESTAMPS
- 00:00: Welcome to SecOps Weekly!
- 04:01: Kerberos Authentication Protocol
- 08:37: What is Kerberoasting?
- 14:13: The persistence problem
- 21:22: How to defend against it