What MITRE CAPEC-509: Kerberoasting (Detailed Attack Pattern - High Severity) requires
MITRE CAPEC-509 (Kerberoasting) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. Through the exploitation of how service accounts leverage Kerberos authentication with Service Principal Names (SPNs), the adversary obtains and subsequently cracks the hashed credentials of a service account target to exploit its privileges. The Kerberos authentication protocol centers around a ticketing system which is used to request/grant access to services and to then access the requested services. Likelihood of attack: Unknown. Typical severity: High. Maps to weaknesses CWE-522, CWE-308, CWE-309, CWE-294, and others. Relates to MITRE ATT&CK T1558.003.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://capec.mitre.org/data/definitions/509.html
SHA-256 integrity: 86171fd28fb197269eaf2e2a3559d3005a99caa87d7da27acb3d3be0d5de87e5
Primary Citations — 12 traced to source
- MITRE CAPEC-509: Kerberoasting (https://capec.mitre.org/data/definitions/509.html)
- CWE-522: underlying weakness (http://cwe.mitre.org/data/definitions/522.html)
+ 10 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.