gMSA
Group Managed Service Account (gMSA) provides automatic password management, SPN management and delegated administration for service accounts across multiple servers
Recommended to protect from Kerberoast type attacks
Kerberoast
Find Accounts
Principals that can read the password blob
Get NTLM Hash
https://www.thehacker.recipes/ad/movement/dacl/readgmsapassword
PtH
Pass the Hash (PtH)BloodyAD
NXC
Extract gmsa credentials accounts
Convert gSAM id, convert gmsa lsa to ntlm ...
Golden gMSA
Only privilege accounts such as Domain Admins, Enterprise Admins or SYSTEM can retrieve the KDS root key.
Last updated
