Emulating and Detecting Kerberoasting | Red Canary
Learn why Kerberoasting is still such a popular attack vector, explore relevant data sources, and uncover visibility gaps by way of Atomic Red Team "Kerberoasting" was first identified by Tim Medin, CEO of @RedSiege, nearly a decade ago, but Conti and other ransomware groups are reportedly leveraging it as part of their modern-day playbook. We explore why this post-exploitation technique is still so popular among adversaries, unpack relevant detection opportunities, and discuss how Atomic Red Team can help shore up your defenses. https://redcanary.com/blog/marshmallo... Kerberoasting (T1558.003)—a post-exploitation technique first identified nearly a decade ago—has reportedly been leveraged by the likes of Conti and Nobelium in recent months. As your security ally, Red Canary enables your team to focus on the highest priority security issues impacting your business. By removing your need to build and manage a threat detection operation, we help you focus on running your business securely and successfully. Our Managed Detection and Response delivers threat detection, hunting, and response—driven by human expert analysis and guidance—applied across your endpoints, cloud, and network security.

Validation Station: Open source threat emulation | Atomic Red Team

Kerberos and Attacks 101 - Tim Medin

From MuddyWater to M396 phishing, our experts weigh in

Attacking AI - Jason Haddix - NDC Security 2026

THESE Apps Are SPYING on You — Shut Them Off NOW!

Emulating Raspberry Robin using Atomic Red Team | Red Canary

Investigating WMI Attacks

Top 10 Ways to Improve Active Directory Security Quickly

ATT&CK Deep Dive: Lateral Movement Pt. 1

DEF CON 33 - Kill List: Hacking an Assassination Site on the Dark Web - Carl Miller, Chris Monteiro

Do VPNs Really Protect Privacy? Data & Cybersecurity Insights

Keynote: Cobalt Strike Threat Hunting | Chad Tilbury

Detect smarter. Detect faster.

SANS Webcast: Kerberos & Attacks 101

How security teams can use the 2026 Threat Detection Report in the wild

Hack Active Directory with LLMNR

Beyond the Mcse: Active Directory for the Security Professional

Kerberos Explained (In 3 Levels Of Detail)

Learn Microsoft Active Directory (ADDS) in 30mins

