T5AI for Cloud & Identity Attack Paths
Kerberos attacks
How the design of Active Directory's authentication protocol becomes an attack surface: Kerberoasting, AS-REP roasting, delegation abuse, and ticket forgery.
Advanced4 min readprofessional streamUpdated Sat Aug 01 2026 00:00:00 GMT+0000 (Coordinated Universal Time)
Learning objectives
- Recall the Kerberos primitives (TGT, TGS, SPN) that make the attacks possible.
- Perform and distinguish Kerberoasting and AS-REP roasting.
- Explain unconstrained, constrained, and resource-based delegation abuse.
- Describe golden and silver ticket forgery as post-compromise techniques.
- Keep credential-class Kerberos actions behind human approval in an AI-assisted flow.
Academy subscription
Subscribe to unlock this module
This module is part of the StrikeOps Academy subscription. Unlock every paid module, with hands-on labs and knowledge checks.
- Every paid module across all tracks
- Hands-on labs and knowledge checks
- New content as it ships
$59/ month · or $590 / year
The Reference library and Foundation starters are free to read now.