← All Lessons
Premium

FoundationalActive Directory

Inside the Kerberos Ticket Exchange (AS and TGS)

Kerberos authentication looks simple from the outside: prove who you are once, get a ticket, use it everywhere. This lesson opens the AS-REQ/AS-REP and TGS-REQ/TGS-REP exchanges message by message, the authenticator, which key encrypts which field, and what each ticket actually contains, the protocol-internals layer that explains why Kerberoasting and AS-REP Roasting work.

Sign in or upgrade to unlock the full premium library.

What you'll learn

  • Authenticator
  • Pre-authentication
  • Session key duplication
  • TGS-REQ authenticator
  • Service ticket encryption key
  • Stateless KDC

What premium includes

  • All 68 lessons: AD techniques, professional skills, each with interview answers and study kits
  • Complete study kit for every lesson: quizzes, flashcards, and briefs
  • Every learning track with full structured progression
  • All 12 attack paths: full compromise walkthroughs for interviews and reports
  • New lessons and attack paths added regularly

Continue with free content