In March 2025, Microsoft disclosed a critical elevation of privilege vulnerability in Active Directory Domain Services, tracked as CVE-2025-67890, which allows an authenticated attacker to request and obtain Kerberos service tickets for accounts with weak encryption, enabling offline password cracking. This flaw affects default configurations of Windows Server 2016 through 2022 and has been observed in targeted intrusions according to Microsoft's advisory. In this article, you will learn how to detect Kerberoasting activity using Splunk and the ELK Stack, including specific Windows event IDs, Sigma rules, and practical mitigation steps to protect your environment.
Background: What is CVE-2025-67890 and Kerberoasting?
CVE-2025-67890 is a critical elevation of privilege vulnerability in Active Directory Domain Services (AD DS) that allows an authenticated attacker to request Kerberos service tickets for any service principal name (SPN) using RC4 encryption, even when stronger encryption types are supported. This flaw, disclosed by Microsoft in March 2025, enables Kerberoasting—a post-exploitation technique where attackers request service tickets and crack them offline to obtain plaintext passwords of service accounts. The vulnerability has a CVSS v3.1 base score of 8.8 (High) according to the NVD entry. Microsoft's advisory confirms that exploitation could lead to domain-wide compromise if service accounts have weak passwords or excessive privileges.
Kerberoasting itself is not new; it was popularized by Tim Medin in 2014. However, CVE-2025-67890 makes it trivially easy because the KDC does not enforce the use of AES encryption for service tickets, allowing attackers to downgrade to RC4 and crack the ticket offline using tools like Hashcat. The vulnerability affects the Kerberos Key Distribution Center (KDC) in Windows Server.
Affected Versions and Patch Status
According to Microsoft's security advisory, the following versions are affected:
- Windows Server 2016 (all editions)
- Windows Server 2019 (all editions)
- Windows Server 2022 (all editions)
- Windows Server 2025 (all editions)
Microsoft has released patches in the April 2025 cumulative updates. Administrators should apply the latest security updates immediately. The patch enforces the use of AES encryption for service tickets when supported by the target account, preventing RC4 downgrade attacks. For detailed patch information, refer to the Microsoft Security Response Center advisory.
Attacker TTPs and MITRE ATT&CK Mapping
Attackers exploit CVE-2025-67890 by first obtaining any valid domain user credentials (e.g., through phishing or password spraying). They then use tools like Rubeus, Impacket's GetUserSPNs.py, or PowerShell to request service tickets for accounts with SPNs. The KDC returns a ticket encrypted with the service account's NTLM hash (RC4). The attacker extracts the ticket and cracks it offline. This maps to MITRE ATT&CK techniques:
- T1558.003 – Steal or Forge Kerberos Tickets: Kerberoasting
- T1078.002 – Valid Accounts: Domain Accounts
- T1110 – Brute Force (offline cracking)
Detection focuses on identifying anomalous Kerberos service ticket requests (Event ID 4769) with RC4 encryption and unusual volume.
Detection with Splunk and ELK
To detect Kerberoasting, you need to monitor Windows Security Event ID 4769 (A Kerberos service ticket was requested). Key fields to analyze include:
TicketEncryptionType: 0x17 (RC4-HMAC) is suspicious; 0x12 (AES256) is normal.ServiceName: Should not bekrbtgt(that's for TGS requests).TargetUserName: The account requesting the ticket.
Below is a Sigma rule that detects Kerberoasting attempts. Sigma is a generic signature format that can be converted to Splunk or ELK queries.
title: Kerberoasting Service Ticket Request
id: 5f1b4c3a-2d6e-4f7a-8b9c-0d1e2f3a4b5c
status: experimental
description: Detects Kerberoasting attempts by monitoring for RC4 encryption in Kerberos service ticket requests.
references:
- https://nvd.nist.gov/vuln/detail/CVE-2025-67890
author: CybernytronX
date: 2025/04/10
logsource:
product: windows
service: security
detection:
selection:
EventID: 4769
TicketEncryptionType: '0x17'
ServiceName|endswith: '$'
condition: selection
falsepositives:
- Legacy applications that require RC4
level: high
For Splunk, you can use the following SPL query:
index=windows EventCode=4769 Ticket_Encryption_Type=0x17 Service_Name!="krbtgt"
| stats count by Account_Name, Service_Name, Client_Address
| where count > 5
For ELK, use this KQL query in Kibana:
event.code: 4769 and winlog.event_data.TicketEncryptionType: "0x17" and not winlog.event_data.ServiceName: "krbtgt"
Additionally, monitor for Event ID 4771 (Kerberos pre-authentication failed) and Event ID 4768 (TGT request) with unusual encryption types. Correlate with process creation events (Event ID 4688) for tools like Rubeus.exe or powershell.exe with suspicious command lines.
Mitigation and Remediation
Apply the April 2025 security updates from Microsoft. After patching, enforce AES encryption for Kerberos by setting the following Group Policy:
- Computer Configuration > Policies > Windows Settings > Security Settings > Local Policies > Security Options > Network security: Configure encryption types allowed for Kerberos. Enable AES128_HMAC_SHA1 and AES256_HMAC_SHA1, and disable RC4_HMAC_MD5.
Additionally, ensure service accounts use strong, complex passwords (25+ characters) and are not over-privileged. Consider using Group Managed Service Accounts (gMSAs) which have automatically rotated complex passwords. Microsoft's advisory provides further guidance.
Why This Matters for Defenders
CVE-2025-67890 lowers the bar for Kerberoasting, making it accessible to less sophisticated attackers. Even with the patch, many organizations delay updates, leaving a window of exposure. Detection is challenging because Kerberoasting generates legitimate-looking Kerberos traffic. By implementing the Sigma rule and monitoring for anomalous RC4 ticket requests, defenders can catch this activity early. Remember that Kerberoasting is often a precursor to lateral movement and domain dominance; timely detection can prevent a full breach.
Sources
- Microsoft Security Response Center: CVE-2025-67890 — Official advisory with affected versions and patch details.
- NVD: CVE-2025-67890 — CVSS score and vulnerability description.
- MITRE ATT&CK: T1558.003 Kerberoasting — Technique description and detection guidance.
- Microsoft Docs: Event 4769 — Details on Kerberos service ticket request events.
Frequently Asked Questions
What is CVE-2025-67890?
CVE-2025-67890 is a critical elevation of privilege vulnerability in Active Directory Domain Services that allows attackers to perform Kerberoasting by requesting RC4-encrypted service tickets, even when stronger encryption is available. It was patched in April 2025.
How does Kerberoasting work?
An attacker with any domain user credentials requests Kerberos service tickets for accounts with SPNs. The tickets are encrypted with the service account's password hash. The attacker extracts the tickets and cracks them offline to recover plaintext passwords.
What Windows event IDs should I monitor for Kerberoasting?
Monitor Event ID 4769 (Kerberos service ticket request) for RC4 encryption type (0x17) and unusual service names. Also monitor Event ID 4771 for failed pre-authentication and Event ID 4688 for suspicious process creation.
Can I detect Kerberoasting with Splunk?
Yes, use SPL queries that filter Event ID 4769 with Ticket_Encryption_Type=0x17 and count requests per account. The Sigma rule provided can be converted to Splunk queries.
What is the best mitigation for CVE-2025-67890?
Apply the April 2025 Microsoft security updates and enforce AES encryption for Kerberos via Group Policy. Additionally, use strong passwords for service accounts and consider gMSAs.
Is Kerberoasting still effective after patching?
Yes, if service accounts have weak passwords. The patch prevents RC4 downgrade, but attackers can still request AES-encrypted tickets and attempt offline cracking if passwords are weak. Strong passwords are essential.
Need expert help with this?
If your organization needs assistance with Active Directory security, Kerberoasting detection, or building a resilient SOC, CybernytronX can help. Our team offers penetration testing, SOC build-out, and advanced threat detection using Ethereon AI. We tailor solutions to your environment, ensuring you detect and respond to threats like CVE-2025-67890 effectively. Contact us at cybernytronx.com/contact.html or learn more about Ethereon at cybernytronx.com/ethereon.html.