Skip to main content
Version: 2.2.1-preview

AD-SPN-01 - Computer SPN service class count should be retrievable

Overviewโ€‹

Service Principal Names (SPNs) are critical for Kerberos authentication in Active Directory. Understanding the distribution of SPN service classes helps security teams:

  • Identify service exposure: Know what services are exposed for Kerberos authentication
  • Detect anomalies: Unusual SPN service classes may indicate unauthorized services or misconfigurations
  • Audit service footprint: Track the services running across your infrastructure
  • Kerberoasting assessment: SPNs are required for Kerberoasting attacks; knowing what exists helps assess risk

Common SPN service classes include HOST, HTTP, LDAP, MSSQLSvc, and CIFS. Unexpected service classes may warrant investigation.

Security Recommendationโ€‹

Regularly audit SPN configurations to ensure:

  • Only authorized services have SPNs registered
  • SPNs are registered on the correct accounts
  • Unused or legacy service SPNs are removed
  • Sensitive SPNs (like those for database services) are properly secured

How the Test Worksโ€‹

This test retrieves all computer objects from Active Directory, extracts their SPNs, and counts the distinct service classes. An SPN has the format serviceclass/host:port, and this test focuses on the service class portion.

  • Test-MtAdComputerSpnServiceClassUsage - Shows usage breakdown of each service class
  • Test-MtAdComputerSpnUnknownCount - Identifies unrecognized SPN service classes
  • Test-MtAdUserSpnServiceClassCount - Counts distinct service classes on user accounts

Test Metadataโ€‹

FieldValue
Test IDAD-SPN-01
SeverityInfo
SuiteActive Directory
CategoryAD.SPN
PowerShell testTest-MtAdComputerSpnServiceClassCount
TagsAD, AD-SPN-01, AD.SPN

Sourceโ€‹

  • Pester test: tests/ad/spn/Test-MtAdComputerSpnServiceClassCount.Tests.ps1
  • PowerShell source: powershell/public/ad/spn/Test-MtAdComputerSpnServiceClassCount.ps1