Set-SPN
With enough rights (generic all/ generic write) a target user's SPN can be set to anything(unique in the domain) then a service ticket can be requested for kerberoasting and getting the account access. How to do it? For exmaple we check outbound rules from bloodhound or run the below powerview command for the RDPUsers group we will see there are some supportx users on domain where rdpusers group has generic all permissions.
Using Powerview, see if the supportuser already has a SPN:
Same using AD module
Now set SPN for that user
Same as above set SPN using AD moudle
After this kerberoast the user
Last updated