Skip to main content
Rapid7Launch

Metasploit 2026 update: new kerberos & certificate tracing

What happened

Rapid7, Inc. launched CertificateTrace on Jun 12th '26.

Source

Article excerpt

Highlighted: the sentence this signal was extracted from

Metasploit 2026 update: new kerberos & certificate tracing - detection and hardening. Security Arsenal Team June 12, 2026 In the June 2026 Metasploit Weekly Update, Rapid7 introduced significant quality-of-life improvements for operators: KerberosTicketTrace and CertificateTrace. While these options are designed to streamline debugging and module development, they represent a maturation of the offensive toolset available to adversaries. By providing granular visibility into Kerberos tickets and digital certificates handled by modules, Metasploit lowers the barrier to successfully exploiting complex Active Directory (AD) environments. For defenders, this update signals a shift. Attackers can now more easily troubleshoot failures in Kerberoasting, Golden Ticket creation, or PKI abuse (ESC1/ESC8) attempts. This blog post breaks down the technical implications of these updates and provides actionable detection and remediation strategies to harden your environment against these evolving techniques. Technical analysis. Affected Products and Platforms: * Metasploit Framework: All versions updating to the June 2026 release. * Target Environment: Primarily Windows Active Directory domains (Windows Server 2016+). New Capabilities: * KerberosTicketTrace: This option enables verbose logging for Kerberos tickets. When a module (e.g., auxiliary/admin/kerberos/get_ticket)...

Keep reading with a free account

The rest of this article, and every signal for Rapid7, is in your free account.

Extracted by Autobound

From the Signal API record
Event
Launch

What this signalsA launch often needs new go-to-market and support spend.

Product
CertificateTrace
Takes effect
Jun 12, 2026

The full record

From the Signal API record

Details

Ticker
NASDAQ:RPD

Extraction

Confidence
69%
Detected
Jun 13, 2026
signal_type
news
signal_subtype
launches

Use this data

Get every launch signal for Rapid7 and the companies you sell to, in the tools you already use.

  1. Ask Claude about it

    Connect Autobound to Claude, Claude Code or Cursor with MCP. Then ask: “What changed at Rapid7 this week?”

  2. Send it to your own tools

    The Signal API returns launch signals for any list of companies as JSON, for your CRM, warehouse or app.

  3. Try it free

    Sign up and spend your free credits on the companies you sell to.

    Start Free1,000 free credits

The API returns more than this page shows

This page shows a preview. The full news record in the Signal API and MCP can also have these 8 fields. Some fields are empty for some signals.

Company

  • linkedin_urlValue in the API
  • industriesValue in the API
  • employee_count_lowValue in the API
  • employee_count_highValue in the API
  • revenueValue in the API
  • descriptionValue in the API

Signal

  • signal_nameValue in the API
  • associationValue in the API
Show the full JSONThe record on this page and the API request

GET /v1/signals/961258c9-a8da-4c25-9f0a-722b5851c5c6 returns this record as JSON. POST /v1/companies/enrich returns every signal for rapid7.com.

{
  "signal_id": "961258c9-a8da-4c25-9f0a-722b5851c5c6",
  "signal_type": "news",
  "signal_subtype": "launches",
  "detected_at": "2026-06-13T01:09:47+00:00",
  "company": {
    "name": "Rapid7",
    "domain": "rapid7.com"
  },
  "data": {
    "url": "https://securityarsenal.com/blog/metasploit-2026-update-new-kerberos-and-certificate-tracing-detection-and-hardening",
    "title": "Metasploit 2026 update: new kerberos & certificate tracing - detection and hardening.",
    "ticker": "NASDAQ:RPD",
    "excerpt": "Metasploit 2026 update: new kerberos & certificate tracing - detection and hardening.\n\nSecurity Arsenal Team\n\nJune 12, 2026\n\nIn the June 2026 Metasploit Weekly Update, Rapid7 introduced significant quality-of-life improvements for operators: KerberosTicketTrace and CertificateTrace. While these options are designed to streamline debugging and module development, they represent a maturation of the offensive toolset available to adversaries. By providing granular visibility into Kerberos tickets and digital certificates handled by modules, Metasploit lowers the barrier to successfully exploiting complex Active Directory (AD) environments.\n\nFor defenders, this update signals a shift. Attackers can now more easily troubleshoot failures in Kerberoasting, Golden Ticket creation, or PKI abuse (ESC1/ESC8) attempts. This blog post breaks down the technical implications of these updates and provides actionable detection and remediation strategies to harden your environment against these evolving techniques.\n\nTechnical analysis.\n\nAffected Products and Platforms:\n\n* Metasploit Framework: All versions updating to the June 2026 release.\n* Target Environment: Primarily Windows Active Directory domains (Windows Server 2016+).\n\nNew Capabilities:\n\n* KerberosTicketTrace: This option enables verbose logging for Kerberos tickets. When a module (e.g., auxiliary/admin/kerberos/get_ticket) interacts...",
    "product": "CertificateTrace",
    "summary": "Rapid7, Inc. launched CertificateTrace on Jun 12th '26.",
    "planning": false,
    "image_url": "https://securityarsenal.com/og-image-v6.jpg",
    "confidence": 0.6902,
    "product_data": {
      "full_text": "CertificateTrace",
      "fuzzy_match": true
    },
    "published_at": "2026-06-13T01:09:47Z",
    "effective_date": "2026-06-12",
    "article_sentence": "In the June 2026 Metasploit Weekly Update, Rapid7 introduced significant quality-of-life improvements for operators: KerberosTicketTrace and CertificateTrace."
  }
}

Long text fields are shortened on this page.

Looking up one signal by its id is free. Enrich costs 2 credits per signal returned; a call with no results is free.