XPN @xpnsec.com · Aug 3

If you're on an engagement, keep an eye out for the SPN HTTP/<company>.kerberos.okta.com. It provides delegated auth to Okta for a compromised AD user (and usually doesn't require MFA when proxied). getST.py -spn HTTP/company.kerberos.okta.com.

3 likes 1 replies

?

Replies

XPN · Aug 3

You can also tell if Kerberos/Delegated Auth has been enabled resolving <company>.kerberos.okta.com, if you get an A record.. you're GTG!