Metasploit 2026 update: new kerberos & certificate tracing - detection and hardening.
Article excerpt
Highlighted: the sentence this signal was extracted from
Metasploit 2026 update: new kerberos & certificate tracing - detection and hardening. Security Arsenal Team June 12, 2026 In the June 2026 Metasploit Weekly Update, Rapid7 introduced significant quality-of-life improvements for operators: KerberosTicketTrace and CertificateTrace. While these options are designed to streamline debugging and module development, they represent a maturation of the offensive toolset available to adversaries. By providing granular visibility into Kerberos tickets and digital certificates handled by modules, Metasploit lowers the barrier to successfully exploiting complex Active Directory (AD) environments. For defenders, this update signals a shift. Attackers can now more easily troubleshoot failures in Kerberoasting, Golden Ticket creation, or PKI abuse (ESC1/ESC8) attempts. This blog post breaks down the technical implications of these updates and provides actionable detection and remediation strategies to harden your environment against these evolving techniques. Technical analysis. Affected Products and Platforms: * Metasploit Framework: All versions updating to the June 2026 release. * Target Environment: Primarily Windows Active Directory domains (Windows Server 2016+). New Capabilities: * KerberosTicketTrace: This option enables verbose logging for Kerberos tickets. When a module (e.g., auxiliary/admin/kerberos/get_ticket)...
Keep reading with a free account
The rest of this article, and every signal for Rapid7, is in your free account.
