Kerberos: The Six-Step Ticket Flow Explained
How Kerberos issues a TGT and then service tickets across six messages, what the AS, TGS and KDC each do, and why clock drift breaks logon.
SERIES
Kerberos is the CISSP topic that keeps paying: understand the protocol once and three attack classes fall into place behind it. This series walks the chain in order: how tickets actually work, how attackers forge the TGT (golden ticket), how they forge service tickets (silver ticket), and how they crack service account passwords offline (Kerberoasting). Read it in sequence and the exam questions start answering themselves.
How Kerberos issues a TGT and then service tickets across six messages, what the AS, TGS and KDC each do, and why clock drift breaks logon.
How a stolen krbtgt hash lets an attacker forge any Kerberos TGT, why no domain controller checks it, and why krbtgt must be reset twice.
How a stolen service account hash forges a service ticket that never reaches the KDC, why that keeps it out of domain logs, and how to catch it.
How any domain user can request a service ticket for an SPN and crack the service account password offline, and why long managed passwords stop it.