Kerberoasting
Requesting service tickets from Active Directory and cracking them offline to recover service account passwords.
Any authenticated domain user can request a ticket for a service account, and that ticket is encrypted with a key derived from the account password. The attacker takes it away and cracks it at leisure, with nothing failing or alerting in the domain.
Service accounts with weak, unchanged passwords and excessive privilege make this devastating. Long random passwords, or better still group managed service accounts, remove the payoff.
Where this comes up
Kerberoasting sits inside our identity and access work. If you are trying to work out what this means for your own environment rather than in the abstract, that is the page worth reading next, and a short call will get you a straight answer faster than either.