← All Lessons
Premium

FoundationalActive Directory

The Kerberos Double Hop Problem

Kerberos tickets are scoped to the exact resource that issued them, and that scoping is what causes the double hop problem: pivot through a Kerberos-authenticated WinRM session and the second hop has no way to prove who you are. This lesson explains why the ticket you receive on the first hop does not travel to the second, and why an NTLM-authenticated hop does not hit the same wall.

Sign in or upgrade to unlock the full premium library.

What you'll learn

  • Ticket Granting Service (TGS) ticket
  • Ticket Granting Ticket (TGT)
  • Double hop
  • NTLM hash reuse
  • Delegation

What premium includes

  • All 68 lessons: AD techniques, professional skills, each with interview answers and study kits
  • Complete study kit for every lesson: quizzes, flashcards, and briefs
  • Every learning track with full structured progression
  • All 12 attack paths: full compromise walkthroughs for interviews and reports
  • New lessons and attack paths added regularly

Continue with free content