An Active Directory technique: any authenticated user can request a service ticket (TGS) for an account that has a servicePrincipalName. The ticket's enc-part is encrypted with the service account's password NTLM hash (RC4-HMAC, etype 23), so it can be cracked offline without touching the domain controller.
GetUserSPNs.py DOMAIN/user:pass -request
hashcat -m 13100 tgs.txt wordlist.txt
Targets weak, never-rotated service-account passwords. Defense: gMSA, long passwords, monitoring RC4 TGS requests.