Setting Object SPN's
Steps to Take
Step 1 - Find Users Who You Have These Privileges Over
# PowerView_dev
Invoke-ACLScanner -ResolveGUIDs | ?{$_.IdentityReferenceName -match '<group>'}Step 2 - Find Out if the User Already Has a SPN
#PowerView_dev
Get-DomainUser -Identity <user> -Properties ServicePrincipalName
# AD Module
Get-ADUser -Identity <user> -Properties ServicePrincipalNameStep 3 - Set a SPN for the User
Step 4 - Check If the User Has a New SPN By Repeating Step 2
Step 5 - Kerberoast the Account
Mitigations
References
Last updated