Microsoft Defender for Identity: Detecting and Preventing Kerberoasting and AS-REP Roasting Attacks

Explore Our Microsoft Cloud Security Training →

Microsoft Defender for Identity (MDI) is a powerful tool in your arsenal against cyber threats. In this blog post, we’ll focus on how to detect, investigate, and prevent Kerberoasting and AS-REP Roasting attacks using MDI.

Understanding Kerberoasting and AS-REP Roasting

Both Kerberoasting and AS-REP Roasting are techniques used by attackers to extract NTLM hashes from service accounts, which can lead to domain compromise. Understanding these attacks is crucial for effective security.

MDI Alerts for Kerberoasting and AS-REP Roasting

MDI provides alerts when suspicious activities related to Kerberoasting and AS-REP Roasting are detected. Investigating these alerts can help you identify potential threats.

Investigating Suspicious Kerberos Ticket Requests in MDI

When an alert is triggered, you should investigate the affected service accounts and ticket requests. This process helps you understand the scope of the potential threat.

Hardening Service Accounts to Prevent Kerberoasting

To minimize the risk of Kerberoasting attacks, it’s essential to harden service accounts by setting passwords to 25+ characters and enabling AES encryption for Kerberos.

Using Advanced Hunting to Find Kerberoasting Activity

Advanced Hunting allows you to search for specific activity patterns across your environment. In this case, it can help you find evidence of Kerberoasting and AS-REP Roasting.

Conclusion

Protecting your organization from cyber threats requires a deep understanding of the techniques attackers use and the tools available to defend against them. With Microsoft Defender for Identity, you have powerful resources at your disposal. Start your journey towards stronger security today:

Explore Our Microsoft Cloud Security Training →

Written by Mohammed Akhter

Founder of ITP Training. 50,000+ students trained across 30+ countries in Microsoft endpoint and cloud security. Learn more →