Without Kerberos, every service might need to know your username and password, that would be a mess.
If you change your password, every service would need to update it. If your account is disabled, every service would need to know.
Instead, Kerberos creates a central authentication system called the KDC (Key Distribution Center).
So basically Users ( Authenticates ) → KDC → TGT ( To User ) → USER ( With TGT ) → KDC → TGS ( To User ) → User ( With TGS ) → Service
Now we will Learn about few Active Directory Attacks