Port 88: Kerberos V5 Key Distribution Center
Port 88 is the Kerberos Key Distribution Center (KDC) port. RFC 4120 requires KDCs to accept requests over both UDP and TCP and says they should listen on port 88. In Windows domains the KDC service runs on domain controllers, where the Authentication Service issues ticket-granting tickets and the Ticket-Granting Service issues service tickets.
Port Details
Security Exposure
Port 88 gives direct access to domain authentication, so it should stay inside trusted networks. MITRE ATT&CK lists Kerberos on 88/TCP among services targeted by password guessing. Any authenticated user can request service tickets for accounts with service principal names and crack them offline (Kerberoasting), and accounts with pre-authentication disabled are exposed to AS-REP roasting.
Hardening
- +Allow port 88 only from internal networks and VPN clients that need domain authentication.
- +Prefer AES Kerberos encryption types over RC4, which MITRE ATT&CK lists as a Kerberoasting mitigation.
- +Give service accounts long, complex passwords (25 or more characters) or use Group Managed Service Accounts.
- +Keep Kerberos pre-authentication enabled on every account and audit changes to that setting.
Monitoring
On domain controllers, audit event 4768 (TGT requested), 4769 (service ticket requested), and 4771 (pre-authentication failed). Bursts of 4769 events with RC4 encryption (0x17) and 4768 events with pre-authentication type 0 indicate Kerberoasting and AS-REP roasting.
Kerberos Vulnerabilities
1 CVEs| CVE | Title | Vendor | CVSS | EPSS | KEV | Published |
|---|---|---|---|---|---|---|
| CVE-2014-6324 | Microsoft Kerberos Key Distribution Center (KDC) Privilege Escalation Vulnerability | - | 8.8 | 87.3% | KEV | 2014-11-18 |
Tools for Auditing and Monitoring Kerberos
BloodHound CE
Free / CommercialAttack path analysis platform that maps identity and privilege relationships across Active Directory, Entra ID, and other platforms through OpenGraph.
Impacket
FreePython library of classes and example tools for the construction, parsing, and interaction with Windows and Active Directory network protocols.
NetExec
Open SourceNetwork service assessment tool for automating authentication checks, credential sprays, and Active Directory evaluations.
Related Tool Categories
Frequently Asked Questions
Is Kerberos TCP or UDP?→
Both. RFC 4120 requires KDCs to accept UDP and TCP requests on port 88, and Microsoft lists the Windows KDC on TCP 88 and UDP 88.
What is Kerberoasting?→
Kerberoasting is requesting Kerberos service tickets for accounts with service principal names and cracking them offline (MITRE ATT&CK T1558.003). Strong service account passwords and AES encryption reduce the risk.
Which Windows events show Kerberos activity?→
Event 4768 records TGT requests, 4769 records service ticket requests, and 4771 records failed pre-authentication. All three are logged on domain controllers.
Which vulnerabilities affect the service on port 88?→
This database lists 1 CVE related to Kerberos, 1 of them confirmed as exploited by CISA. Examples: CVE-2014-6324.
Sources
- IANA Service Name and Transport Protocol Port Number Registry (port 88)
- RFC 4120: The Kerberos Network Authentication Service (V5)
- Microsoft Learn: Service overview and network port requirements for Windows
- Microsoft Learn: Kerberos authentication overview
- Microsoft Learn: 4768(S, F) A Kerberos authentication ticket (TGT) was requested
- Microsoft Learn: 4769(S, F) A Kerberos service ticket was requested
- Microsoft Learn: 4771(F) Kerberos pre-authentication failed
- MITRE ATT&CK T1558.003: Kerberoasting
- MITRE ATT&CK T1558.004: AS-REP Roasting
- MITRE ATT&CK T1110.001: Brute Force, Password Guessing
Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 88 is not guaranteed to be Kerberos. Exploited-in-the-wild data from the CISA KEV catalog (CC0).