T1558.003: T1558.003
Essential information
- MITRE technique ID
T1558.003- Confidence
- 100/100
- Revoked
- No
- Published
- 16/12/2025 19:38
- Modified
- 20/04/2026 12:52
- Author / Source
- The MITRE Corporation
Aliases
Kerberoasting
Platforms
windows
Description
Kill chain phases
| Kill chain | Phase |
|---|---|
| mitre-attack | credential-access |
Marking (TLP)
TLP:CLEAR Copyright 2015-2025, The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation.
External references
Related entities
Intrusion sets, malware, reports, vulnerabilities, indicators and other entities linked to this technique.
Intrusion sets (APT) (9)
-
The MITRE Corporation Confidence 100
[Magic Hound](https://attack.mitre.org/groups/G0059) is an Iranian-sponsored threat group that conducts long term, resource-intensive cyber espionage operations, likely on behalf of the Islamic Revolutionary Guard Corps. They have targeted European, …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 27/03/2026 01:13 -
medusa usesRansomware.Live Confidence 100
No description available
First seen 01/01/1970 · Last seen 16/11/5138 Published 20/12/2025 08:55 · Modified 21/12/2025 07:18 -
The MITRE Corporation Confidence 100
[Inception](https://attack.mitre.org/groups/G0100) is a cyber espionage group active since at least 2014. The group has targeted multiple industries and governmental entities primarily in Russia, but has also been active …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 25/05/2026 11:50 -
The MITRE Corporation Confidence 100
[Wizard Spider](https://attack.mitre.org/groups/G0102) is a Russia-based financially motivated threat group originally known for the creation and deployment of [TrickBot](https://attack.mitre.org/software/S0266) since at least 2016. [Wizard Spider](https://attack.mitre.org/groups/G0102) possesses a diverse arsenal …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 04/05/2026 16:33 -
The MITRE Corporation Confidence 100
[FIN7](https://attack.mitre.org/groups/G0046) is a financially-motivated threat group that has been active since 2013. [FIN7](https://attack.mitre.org/groups/G0046) has targeted the retail, restaurant, hospitality, software, consulting, financial services, medical equipment, cloud services, media, …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 27/03/2026 01:13 -
The MITRE Corporation Confidence 100
The Akira ransomware group is said to have emerged in March 2023, and there's much speculation about its ties to the former CONTI ransomware group.<br> <br> It's worth …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 27/03/2026 01:13 -
The MITRE Corporation Confidence 100
[Indrik Spider](https://attack.mitre.org/groups/G0119) is a Russia-based cybercriminal group that has been active since at least 2014. [Indrik Spider](https://attack.mitre.org/groups/G0119) initially started with the [Dridex](https://attack.mitre.org/software/S0384) banking Trojan, and then by 2017 …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 27/03/2026 01:13 -
Fog ransomware group usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 13:54 · Modified 21/12/2025 13:54
-
StormBamboo usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 06:17 · Modified 21/12/2025 06:17
Malware (36)
-
Get-DataInfo.ps1 usesFamilyPublished 27/08/2024 08:35 · Modified 27/08/2024 08:35
-
RELOADEXT usesFamilyPublished 05/08/2024 11:29 · Modified 05/08/2024 11:29
-
ReverseSocks usesFamilyPublished 22/05/2026 13:08 · Modified 22/05/2026 13:08
-
POCOSTICK usesFamilyPublished 05/08/2024 11:29 · Modified 05/08/2024 11:29
-
CoolClient usesFamilyPublished 14/05/2026 11:16 · Modified 14/05/2026 11:16
-
TukTuk usesFamilyPublished 11/05/2026 16:15 · Modified 11/05/2026 16:15
-
Rubeus usesFamilyPublished 30/04/2026 10:11 · Modified 30/04/2026 10:11
-
The Gentlemen usesFamilyPublished 28/05/2026 19:56 · Modified 28/05/2026 19:56
-
NetExec usesFamilyPublished 11/05/2026 16:15 · Modified 11/05/2026 16:15
-
Megazord usesFamilyPublished 03/12/2024 16:35 · Modified 03/12/2024 16:35
-
TangleBot usesFamilyPublished 26/06/2024 08:23 · Modified 26/06/2024 08:23
-
ValleyRAT usesFamilyPublished 08/06/2026 10:30 · Modified 08/06/2026 10:30
-
mimikatz usesFamilyPublished 11/05/2026 16:15 · Modified 11/05/2026 16:15
-
CloudAtlas usesFamilyPublished 17/04/2026 18:56 · Modified 17/04/2026 18:56
-
VBCloud usesFamilyPublished 22/05/2026 13:08 · Modified 22/05/2026 13:08
-
Sliver usesFamilyPublished 12/06/2026 21:29 · Modified 12/06/2026 21:29
-
SharpHound usesFamilyPublished 16/01/2026 13:31 · Modified 16/01/2026 13:31
-
Fog ransomware usesFamilyPublished 28/04/2025 04:42 · Modified 28/04/2025 04:42
-
MgBot usesFamilyPublished 17/04/2026 18:56 · Modified 17/04/2026 18:56
-
ToneShell usesFamilyPublished 17/04/2026 18:56 · Modified 17/04/2026 18:56
-
Rclone usesFamilyPublished 11/05/2026 16:15 · Modified 11/05/2026 16:15
-
Medusa usesFamilyPublished 06/04/2026 20:26 · Modified 06/04/2026 20:26
-
EtherRAT usesFamilyPublished 16/06/2026 14:27 · Modified 16/06/2026 14:27
-
SystemBC usesFamilyPublished 12/06/2026 21:29 · Modified 12/06/2026 21:29
-
AdaptixC2 usesFamilyPublished 08/06/2026 10:30 · Modified 08/06/2026 10:30
- MacMa
-
AlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 20/12/2025 19:39 · Modified 27/05/2026 21:40
-
PowerShower - S0441 usesFamilyPublished 22/05/2026 13:08 · Modified 22/05/2026 13:08
-
ABCDoor usesFamilyPublished 08/06/2026 10:30 · Modified 08/06/2026 10:30
-
NetSupport RAT usesFamilyPublished 22/05/2026 13:08 · Modified 22/05/2026 13:08
-
PhantomHeart usesFamilyPublished 22/05/2026 13:08 · Modified 22/05/2026 13:08
-
MacMa - S1016 usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 06:04 · Modified 21/12/2025 06:04
-
BlackSuit usesFamilyPublished 07/08/2025 18:57 · Modified 07/08/2025 18:57
-
PowerCloud usesFamilyPublished 22/05/2026 13:08 · Modified 22/05/2026 13:08
-
Akira - S1129 usesFamilyPublished 03/12/2024 16:35 · Modified 03/12/2024 16:35
-
VBShower - S0442 usesFamilyPublished 17/04/2026 18:56 · Modified 17/04/2026 18:56
Reports (9)
-
AlienVault Confidence 100 20 MITREs 7 IOCs 7 ObservablesPublished 19/06/2026 20:47 · threat-report
-
3 CVEs 20 MITREs 8 Malwares 17 Observables 1 APTPublished 22/05/2026 13:08 · Modified 25/05/2026 09:52
-
AlienVault Confidence 100 1 CVE 23 MITREs 6 Malwares 32 IOCs 32 ObservablesPublished 11/05/2026 18:15 · Modified 11/05/2026 19:28 · threat-report
-
20 MITREs 8 MalwaresPublished 17/04/2026 18:56 · Modified 20/04/2026 10:53
-
18 MITREs 12 Observables 1 APTPublished 04/12/2024 20:41 · Modified 04/12/2024 21:44
-
4 CVEs 18 MITREs 2 Malwares 44 Observables 1 APTPublished 03/12/2024 16:35 · Modified 03/12/2024 16:54
-
BlackSuit Ransomware related25 MITREs 6 Malwares 16 ObservablesPublished 27/08/2024 08:35 · Modified 27/08/2024 09:06
-
1 CVE 15 MITREs 5 Malwares 2 Observables 1 APTPublished 05/08/2024 11:29 · Modified 05/08/2024 11:35
-
A New Compact Variant Discovered related8 MITREs 2 Malwares 50 Observables 1 APTPublished 26/06/2024 08:23 · Modified 26/06/2024 08:56
Vulnerabilities (CVE) (11)
xrdp is an open source RDP server. xrdp before v0.10.5 contains an unauthenticated stack-based buffer overflow vulnerability. The issue stems from improper …
- Attack vector
- Network
- Published
- 27/01/2026
- Modified
- 25/05/2026
An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to …
- Attack vector
- Network
- Published
- 18/11/2024
- Modified
- 21/12/2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, …
- Attack vector
- Network
- Published
- 05/12/2025
- Modified
- 29/05/2026
Microsoft Active Directory Domain Services contains an unspecified vulnerability that allows for privilege escalation.
- Published
- 11/04/2022
- Modified
- 20/12/2025
Microsoft's Netlogon Remote Protocol (MS-NRPC) contains a privilege escalation vulnerability when an attacker establishes a vulnerable Netlogon secure channel connection to a …
- Attack vector
- Local
- Published
- 03/11/2021
- Modified
- 27/05/2026
Microsoft Active Directory Domain Services contains an unspecified vulnerability that allows for privilege escalation.
- Published
- 11/04/2022
- Modified
- 20/12/2025
A privilege escalation vulnerability in Palo Alto Networks PAN-OS software allows a PAN-OS administrator with access to the management web interface to …
- Attack vector
- Network
- Published
- 18/11/2024
- Modified
- 21/12/2025
Cisco Adaptive Security Appliance and Firepower Threat Defense contain an unauthorized access vulnerability that could allow an unauthenticated, remote attacker to conduct …
- Attack vector
- Network
- Published
- 13/09/2023
- Modified
- 21/12/2025
Palo Alto Networks PAN-OS GlobalProtect feature contains a command injection vulnerability that allows an unauthenticated attacker to execute commands with root privileges …
- Attack vector
- Network
- Published
- 12/04/2024
- Modified
- 21/12/2025
Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an information disclosure vulnerability. An attacker could retrieve memory contents on …
- Published
- 15/02/2024
- Modified
- 21/12/2025
Microsoft Office contains a memory corruption vulnerability due to the way objects are handled in memory. Successful exploitation allows for remote code …
- Published
- 03/11/2021
- Modified
- 20/12/2025
Attack patterns (MITRE) (1)
-
Steal or Forge Kerberos Tickets subtechnique-ofT1558
Tool (6)
-
Impacket usesThe MITRE Corporation Confidence 100
[Impacket](https://attack.mitre.org/software/S0357) is an open source collection of modules written in Python for programmatically constructing and manipulating network protocols. [Impacket](https://attack.mitre.org/software/S0357) contains several tools for remote service execution, Kerberos manipulation, …
Published 31/01/2019 02:39 · Modified 27/03/2026 01:07 -
Brute Ratel C4 usesThe MITRE Corporation Confidence 100
[Brute Ratel C4](https://attack.mitre.org/software/S1063) is a commercial red-teaming and adversarial attack simulation tool that first appeared in December 2020. [Brute Ratel C4](https://attack.mitre.org/software/S1063) was specifically designed to avoid detection by …
Published 07/02/2023 21:26 · Modified 27/03/2026 01:07 -
Empire usesThe MITRE Corporation Confidence 100
[Empire](https://attack.mitre.org/software/S0363) is an open-source, cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python, the post-exploitation agents …
Published 16/12/2025 19:37 · Modified 27/03/2026 01:07 -
PowerSploit usesThe MITRE Corporation Confidence 100
[PowerSploit](https://attack.mitre.org/software/S0194) is an open source, offensive security framework comprised of [PowerShell](https://attack.mitre.org/techniques/T1059/001) modules and scripts that perform a wide range of tasks related to penetration testing such as code …
Published 18/04/2018 19:59 · Modified 27/03/2026 01:07 -
Rubeus usesThe MITRE Corporation Confidence 100
[Rubeus](https://attack.mitre.org/software/S1071) is a C# toolset designed for raw Kerberos interaction that has been used since at least 2020, including in ransomware operations.(Citation: GitHub Rubeus March 2023)(Citation: FireEye KEGTAP …
Published 29/03/2023 22:19 · Modified 27/03/2026 01:07 -
SILENTTRINITY usesThe MITRE Corporation Confidence 100
[SILENTTRINITY](https://attack.mitre.org/software/S0692) is an open source remote administration and post-exploitation framework primarily written in Python that includes stagers written in Powershell, C, and Boo. [SILENTTRINITY](https://attack.mitre.org/software/S0692) was used in a …
Published 16/12/2025 19:37 · Modified 27/03/2026 01:07
Campaign (3)
- Operation Wocao uses
- SolarWinds Compromise uses
- Leviathan Australian Intrusions uses
Course Of Action (3)
- Password Policies mitigates
- Encrypt Sensitive Information mitigates
- Privileged Account Management mitigates