A power-shell script to detect systems that are vulnerable to KDC spoofing.
This script must be run on the Domain Controller. For good results “Audit Kerberos Authentication Service” and “Audit Kerberos Service Ticket Operations’ must be enabled with at least “Success” auditing.
For any questions about analyzing the results, please email [email protected]