Cypher: Kerberoastable Users

List every kerberoastable user in the domain (has a SPN, not krbtgt). Pair with hasLAPS / admincount / enabled filters for triage.

Tool
MATCH
Category
Enumeration / BloodHound Cypher Queries
Platform
cross-platform
Requires
no credentials

Open in Command Manager

Syntax

Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.

MATCH (u:User {hasspn:true}) WHERE NOT u.name STARTS WITH 'KRBTGT' RETURN u.name, u.serviceprincipalnames ORDER BY u.name

Credential variants

The same attack using a different authentication material.

Only Privileged Kerberoastable

MATCH (u:User {hasspn:true}) WHERE u.admincount=true AND NOT u.name STARTS WITH 'KRBTGT' RETURN u.name, u.serviceprincipalnames

Kerberoastable + Path to DA

MATCH p=shortestPath((u:User {hasspn:true})-[*1..]->(g:Group)) WHERE g.name CONTAINS 'DOMAIN ADMINS' RETURN p

Examples

MATCH (u:User {hasspn:true}) WHERE NOT u.name STARTS WITH 'KRBTGT' RETURN u.name, u.serviceprincipalnames

Tags

bloodhound cypher kerberoast spn graph

References