NetExec timeroast Module

Timeroast: brute computer-account passwords via the MS-SNTP authenticated NTP exchange. The DC signs replies with the machine-account RC4 key derived from its password, which can be cracked offline. No prior credentials required — the DC will sign for any computer RID you specify.

Tool
nxc
Category
Credential Attacks / Hash Dumping
Platform
linux
Requires
no credentials
Protocols
SMB

Open in Command Manager

Syntax

Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.

nxc smb <dc-ip> -u '' -p '' -M timeroast

Examples

nxc smb 10.10.10.10 -u '' -p '' -M timeroast

Tags

netexec nxc timeroast ms-sntp machine-account offline-cracking

References