Last scan · today Export
Security · Kerberos

Kerberos & passwords

Password policy, krbtgt and Kerberos exposure

Default password policy
Minimum length8 characters
Complexity requiredEnabled
Maximum age365 j
History24
Lockout threshold10 attempts
Reversible encryptionDisabled
krbtgt account
34
jours
krbtgt password age
May 12, 2026
Max ticket lifetime10 h · renew 7 j
Kerberos surface
Kerberoastable accounts · T1558.003
28
Kerberoastable accounts
AS-REP roastable accounts · T1558.004
12
AS-REP roastable accounts
Unconstrained delegation · T1558.001
7
Unconstrained
Accounts with SPN
53
SPN