Skip to content

Attack Tools

Active Directory environments are vulnerable to Kerberoasting and AS-REP roasting attacks, which exploit weaknesses in Kerberos ticket granting. These attacks rely on tools like CrackMapExec, Impacket, and Mimikatz to request service tickets, extract hashes, and crack them offline. Below are practical examples of how these tools are used in lab environments.


CrackMapExec for Kerberoasting

CrackMapExec (CME) automates Kerberoasting by requesting TGS tickets for service accounts.

Step 1: Enumerate SPNs

cme kerberos <DC_IP> --spns
This identifies service principal names (SPNs) associated with domain accounts.

Step 2: Request TGS Tickets

cme kerberos <DC_IP> --spns <SPN>
CrackMapExec will request a TGS ticket for the specified SPN. Use --export to save the ticket to a file:
cme kerberos <DC_IP> --spns <SPN> --export <output_file>

Step 3: Crack Hashes
Use tools like John the Ripper or hashcat to crack the exported hashes:

john --wordlist=wordlist.txt <output_file>


Impacket for Kerberoasting and AS-REP Roasting

Impacket provides utilities like GetUserSPN.py and GetTGT.py for Kerberoasting, while klist can list Kerberos tickets.

Kerberoasting Example
1. Find SPNs:

GetUserSPN.py -dcip <DC_IP>
This outputs SPNs like HTTP/somehost.domain.com.

  1. Request TGS Ticket:
    GetTGT.py -dcip <DC_IP> -spn HTTP/somehost.domain.com
    
    The tool will export the ticket hash for cracking.

AS-REP Roasting Example
Use klist to list Kerberos tickets and extract hashes:

klist -k <ticket_file>
For AS-REP roasting, Mimikatz is typically used (see below).


Mimikatz for Kerberoasting and AS-REP Roasting

Mimikatz is a versatile tool for interacting with Kerberos tickets.

Kerberoasting Example
1. Request TGS Ticket:

kerberos::ts request /target:HTTP/somehost.domain.com
This generates a TGS ticket for the SPN.

  1. Export Ticket:
    Use kerberos::list /export to save the ticket to a file for offline cracking.

AS-REP Roasting Example
AS-REP roasting targets accounts with NTLM authentication enabled. Use:

kerberos::list /export
This exports hashes in the AS-REP format, which can be cracked with tools like Hashcat.


Key takeaways

  • CrackMapExec automates Kerberoasting by requesting TGS tickets and exporting hashes.
  • Impacket tools like GetUserSPN.py and GetTGT.py are critical for identifying SPNs and extracting tickets.
  • Mimikatz provides granular control over Kerberos tickets, enabling both Kerberoasting and AS-REP roasting.
  • All tools require domain access and proper permissions to request tickets.
  • Lab environments are essential for safely testing these techniques without compromising production systems.