Skip Navigation
Get a Demo

Join the Zscaler Agentic SecOps Launch Event: ⚡ ️Machine-speed protection 🧠 Elite Red Canary expertise.

Save my seat >>
 
 
 
 
 
 
 
 
 
Resources Videos
Security operations

SecOps Weekly: Episode 75 – Why Kerberoasting is still everywhere in 2026

SecOps Weekly | 08.4.26

Why Kerberoasting is still everywhere in 2026

Tim Medin, CEO of Red Siege Information Security, on why Kerberoasting, a cyberattack that targets the Kerberos authentication protocol in Windows Active Directory environments, is still a concern for SecOps teams in 2026.

SHOW NOTES

What is Kerberoasting and why is it still wrecking enterprise networks? In this episode of SecOps Weekly, Red Siege CEO Tim Medin explains why Kerberoasting — an attack targeting the Kerberos authentication protocol in Windows Active Directory environments — remains a prevalent threat for SecOps teams more than a decade after he coined the term. The conversation covers how attackers exploit service tickets (TGS) to perform offline cracking of password hashes, particularly when weak RC4 encryption is used.

TIMESTAMPS

  • 00:00: Welcome to SecOps Weekly!
  • 04:01: Kerberos Authentication Protocol
  • 08:37: What is Kerberoasting?
  • 14:13: The persistence problem
  • 21:22: How to defend against it

Security gaps? We got you.

Sign up for our monthly email newsletter for expert insights on MDR, threat intel, and security ops—straight to your inbox.


 
 
Back to Top