Kerbrute Password Spray
Password spray a single password against a list of users via Kerberos (avoids lockout, no failed logon events)
- Tool
- kerbrute
- Category
- Authentication / Brute Force & Spraying
- Platform
- linux
- Requires
- no credentials
- Protocols
- KERBEROS
Syntax
Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.
kerbrute passwordspray -d '<domain>' --dc '<ip>' '<userlist>' '<password>'
Examples
kerbrute passwordspray -d 'CORP.LOCAL' --dc '192.168.1.100' users.txt 'Password123'
Tags
Related commands
- Impacket Secrets Dump Dump hashes from remote Windows system (SAM, LSA, NTDS)
- Evil-WinRM Shell Windows Remote Management shell connection
- NetExec SMB Brute Force SMB password brute force attack
- NetExec SMB Password Spray Spray a single password against multiple users via SMB, continuing on valid hits