Kerberoasting Commands
12 Kerberoasting commands from the Credential Attacks category, each with its placeholders, supported authentication methods and upstream references.
Tools covered: Rubeus.exe, impacket-GetNPUsers, impacket-GetUserSPNs, impacket-getTGT, impacket-keylistattack, nxc, python
- Impacket AS-REP Roast AS-REP Roasting for accounts without Kerberos Pre-Authentication
- Impacket Get TGT Get TGT to be used in Kerberos authentication
- Impacket Kerberoast Extract service account hashes via Kerberoasting
- Impacket KeyListAttack Abuse RODC (Read-Only DC) credential caching to retrieve hashes for accounts cached on the RODC
- Impacket Targeted Kerberoast Request a TGS only for a specific service account instead of every kerberoastable user in the domain.…
- NetExec LDAP AS-REP Roasting Request AS-REP responses for every account with DONT_REQ_PREAUTH set and write hashes to a file ready for…
- NetExec LDAP Kerberoasting Request TGS tickets for every account with a SPN and write hashes to a file ready for hashcat (-m 13100).…
- NetExec LDAP Pre-Windows 2000 Accounts Enumerate pre-Windows 2000 compatible computer accounts that use the hostname as password
- NetExec SMB Timeroast Exploit NTP to request hashes for computer accounts without a password (Timeroasting)
- Rubeus asktgt Request a TGT for a user with a password, NT hash, or AES key. /ptt injects it into the current session;…
- Rubeus kerberoast Roast every kerberoastable account in the domain from a Windows host. Auto-discovers SPNs via LDAP and dumps…
- Targeted Kerberoast Targeted Kerberoasting attack on specific accounts