-
Notifications
You must be signed in to change notification settings - Fork 1
kerberos snoop
Kerberos is the authentication protocol behind every Active
Directory environment. Clients exchange messages with a Key
Distribution Center (KDC, typically the domain controller) on
TCP / UDP port 88. Sloth's first pass at Kerberos visibility is
narrow: detect each Kerberos message type via the outer ASN.1
[APPLICATION] tag, parse the KRB-ERROR error code, and fire
KERB_PREAUTH_BURST when a single source produces a clean burst
of KDC_ERR_PREAUTH_FAILED responses (password spray).
Deeper Kerberos visibility — username/principal extraction, AS-REP roasting detection, and kerberoasting service-ticket tracking — is documented out of scope at the bottom of this page.
Kerberos messages are tagged with an outer
[APPLICATION n] constructed identifier. Sloth recognises the
five operationally interesting ones by their first byte:
| Tag byte | Message | RFC 4120 § |
|---|---|---|
0x6A |
AS-REQ | 5.4.1 |
0x6B |
AS-REP | 5.4.2 |
0x6C |
TGS-REQ | 5.4.1 |
0x6D |
TGS-REP | 5.4.2 |
0x7E |
KRB-ERROR | 5.9.1 |
For TCP/88 the wire format prefixes the Kerberos message with a 4-byte length; the parser checks for the magic tag at offset 0 or 4 to handle both transports.
When the message is a KRB-ERROR, we walk for the [6] error-code
field (DER: A6 LEN 02 ilen <bytes>) and bucket the code:
| Error | Code | Bucket |
|---|---|---|
KDC_ERR_PREAUTH_REQUIRED |
25 | preauth_required_count |
KDC_ERR_PREAUTH_FAILED |
24 | preauth_failed_count |
KDC_ERR_C_PRINCIPAL_UNKNOWN |
6 | principal_unknown_count |
| (any other) | … | error_other_count |
Per-source aggregation: every flow with a Kerberos message on
port 88 contributes to a kerb_event keyed on the client IP
(whichever endpoint is NOT on port 88). Up to 64 sources
tracked; oldest-evicted on overflow.
KERB_PREAUTH_BURST: 10.0.0.5: 12 Kerberos pre-auth failures
(spray indicator; unknown-principal=2, preauth-required=3)
| Field | Value |
|---|---|
| Severity | CRIT |
| Threshold |
preauth_failed_count ≥ 5 per source |
| Dedup key |
kerb-burst:<src_ip> — one alert per spraying source |
match_ip |
src_ip (the spray origin to investigate) |
match_port |
88 |
Why 5: a human mistyping their password and getting it right on the third attempt produces at most 2 failures from a single workstation, then succeeds. Five preauth failures across the active aggregation window is a clean signal of automated iteration over a username list.
- Per-user aggregates with
preauth_required_count > 0andpreauth_failed_countlow (0–2). The PREAUTH_REQUIRED response is the standard "you need to include pre-auth data" reply to a first AS-REQ without it; every successful authentication produces one. -
as_req_count≈as_rep_count + preauth_required_count + preauth_failed_count. (REP responses are sent when pre-auth succeeds.) - TGS-REQ / TGS-REP counts grow with the number of service tickets the client is granted — file shares, RPC endpoints, web SPNs.
-
preauth_failed_count ≥ 5from one source — fires the alert. -
principal_unknown_count > preauth_failed_countfrom one source — username enumeration sweep ("doesaaronexist?abby?adam?"). Not currently a dedicated alert; thekerb_eventrecord exposes the count for ops to grep on in the SIEM. - High
tgs_req_countfrom a workstation that hasn't shown corresponding AS-REQ traffic — possible kerberoasting (an attacker with a stolen TGT requesting service tickets en masse). Not currently a dedicated alert.
-
Username / principal extraction. AS-REQ carries the
cnamefield in plaintext; parsing it requires walking the ASN.1KDC-REQ-BODYpast thepadata. The aggregate counts are enough for the burst alert; per-username detail would be nice for the SIEM but isn't on the critical path. - AS-REP roasting (CVE-free attack class). Detection requires correlating an AS-REP returned WITHOUT a prior PREAUTH_REQUIRED error from the same client — needs request / response pairing the v1 tracker doesn't currently maintain. Documented as the natural Tier 2 follow-up.
-
Kerberoasting detection — service-ticket request volumes,
weak encryption (
etype=23RC4-HMAC) flagging. Same Tier 2 bucket. - Pre-auth bypass via NTLM fallback — out of scope for the Kerberos parser; NTLMSSP travels inside SMB and would land in the SMB snooper's NTLMSSP follow-up.
Each is a tractable Tier 2 follow-up; the kerb_event JSONL
record already carries the counters needed for SIEM correlation
queries to surface them without C code changes.
- RFC 4120 — The Kerberos Network Authentication Service (V5).
- RFC 4757 — RC4-HMAC encryption types (kerberoasting target).
- MITRE ATT&CK T1110.003 — Password Spraying.
- MITRE ATT&CK T1558.003 — Kerberoasting.
- MITRE ATT&CK T1558.004 — AS-REP Roasting.
- alerts — the rule that fires on the tracker's state.
-
jsonl-schema —
kerb_eventwire format. - smb-snoop — companion lateral-movement page; SMB and Kerberos travel together in AD environments.
- ipv6-ndp — the other recently-landed passive observable.
Mirrored from docs/wiki/ on main by .github/scripts/wiki_sync.sh. Edit there, not here — hand edits to this wiki are overwritten on the next push.
Read this first — the complete reference
- what-sloth-does
- how-wifi-works
- monitor-mode
- where-exploits-happen
- wifi-sigint-techniques
- cli-reference
- wifi-state-of-the-art
Start here
Engines
WiFi SIGINT
- wifi-sigint
- non-ip-sensors
- mac-randomisation
- evil-twin-reproducer
- btm-abuse
- action-frames
- research-corpus
- captive-portal
- fragattacks
- tool-fingerprints
- enterprise-rogue
- ipv6-ndp
- smb-snoop
- kerberos-snoop
- ldap-snoop
- bgp-snoop
- ssh-snoop
- rdp-snoop
- snmp-snoop
- mqtt-snoop
UI and infrastructure
- ip-palette
- platform-vtable
- version-checkin
- manifest-format
- pcap-export
- jsonl-schema
- data-socket-exposure
- sqlite-schema
- ring-buffers
Factory infrastructure
Reference
Source material
Maintenance