Catalog WADComs

WAD · Tool

targetedKerberoast

1 technique Linux · ActiveDirectory · WindowsWADComs GPL-3.0

Execution

Execution LinuxActiveDirectoryWindows

targetedKerberoast is a Python script that can, like many others (e.g. GetUserSPNs.py), print "kerberoast" hashes for user accounts that have a SPN set. This tool brings the following additional feature: for each user without SPNs, it tries to set one (abuse of a write permission on the servicePrincipalName attribute), print the "kerberoast" hash, and delete the temporary SPN set for that operation. Command Reference: Target IP: 10.10.10.1 Attacker IP: 10.10.10.2 Domain: test.local Username: john Password: password123

python3 targetedKerberoast.py -d test.local -u john -p password123 --dc-ip 10.10.10.1
Native
Exploitation
Requires
Password, Username
Services
Kerberos, NTLM