Skip to main content

Port Details

Port
88
Transport
TCP / UDP
Service
Kerberos
IANA service name
kerberos
Range
System port (0-1023)
Related ports

Security Exposure

Port 88 gives direct access to domain authentication, so it should stay inside trusted networks. MITRE ATT&CK lists Kerberos on 88/TCP among services targeted by password guessing. Any authenticated user can request service tickets for accounts with service principal names and crack them offline (Kerberoasting), and accounts with pre-authentication disabled are exposed to AS-REP roasting.

Hardening

  • +Allow port 88 only from internal networks and VPN clients that need domain authentication.
  • +Prefer AES Kerberos encryption types over RC4, which MITRE ATT&CK lists as a Kerberoasting mitigation.
  • +Give service accounts long, complex passwords (25 or more characters) or use Group Managed Service Accounts.
  • +Keep Kerberos pre-authentication enabled on every account and audit changes to that setting.

Monitoring

On domain controllers, audit event 4768 (TGT requested), 4769 (service ticket requested), and 4771 (pre-authentication failed). Bursts of 4769 events with RC4 encryption (0x17) and 4768 events with pre-authentication type 0 indicate Kerberoasting and AS-REP roasting.

Kerberos Vulnerabilities

1 CVEs
CVETitleVendorCVSSEPSSKEVPublished
CVE-2014-6324
Microsoft Kerberos Key Distribution Center (KDC) Privilege Escalation Vulnerability
-8.887.3%KEV2014-11-18

Tools for Auditing and Monitoring Kerberos

BloodHound CE

Free / Commercial
Red Teaming Tools

Attack path analysis platform that maps identity and privilege relationships across Active Directory, Entra ID, and other platforms through OpenGraph.

LicenseApache-2.0
PlatformLinux, macOS, Windows
Penetration Testing Tools

Python library of classes and example tools for the construction, parsing, and interaction with Windows and Active Directory network protocols.

LicenseModified Apache-1.1 (custom; see repo LICENSE)
PlatformLinux, macOS, Windows

NetExec

Open Source
Penetration Testing Tools

Network service assessment tool for automating authentication checks, credential sprays, and Active Directory evaluations.

LicenseBSD-2-Clause
PlatformLinux, macOS, Windows

Frequently Asked Questions

Is Kerberos TCP or UDP?→

Both. RFC 4120 requires KDCs to accept UDP and TCP requests on port 88, and Microsoft lists the Windows KDC on TCP 88 and UDP 88.

What is Kerberoasting?→

Kerberoasting is requesting Kerberos service tickets for accounts with service principal names and cracking them offline (MITRE ATT&CK T1558.003). Strong service account passwords and AES encryption reduce the risk.

Which Windows events show Kerberos activity?→

Event 4768 records TGT requests, 4769 records service ticket requests, and 4771 records failed pre-authentication. All three are logged on domain controllers.

Which vulnerabilities affect the service on port 88?→

This database lists 1 CVE related to Kerberos, 1 of them confirmed as exploited by CISA. Examples: CVE-2014-6324.

Sources

Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 88 is not guaranteed to be Kerberos. Exploited-in-the-wild data from the CISA KEV catalog (CC0).