Attack Tools
Active Directory environments are vulnerable to Kerberoasting and AS-REP roasting attacks, which exploit weaknesses in Kerberos ticket granting. These attacks rely on tools like CrackMapExec, Impacket, and Mimikatz to request service tickets, extract hashes, and crack them offline. Below are practical examples of how these tools are used in lab environments.
CrackMapExec for Kerberoasting¶
CrackMapExec (CME) automates Kerberoasting by requesting TGS tickets for service accounts.
Step 1: Enumerate SPNs
Step 2: Request TGS Tickets
--export to save the ticket to a file:Step 3: Crack Hashes
Use tools like John the Ripper or hashcat to crack the exported hashes:
Impacket for Kerberoasting and AS-REP Roasting¶
Impacket provides utilities like GetUserSPN.py and GetTGT.py for Kerberoasting, while klist can list Kerberos tickets.
Kerberoasting Example
1. Find SPNs:
HTTP/somehost.domain.com.
- Request TGS Ticket:
The tool will export the ticket hash for cracking.
AS-REP Roasting Example
Use klist to list Kerberos tickets and extract hashes:
Mimikatz for Kerberoasting and AS-REP Roasting¶
Mimikatz is a versatile tool for interacting with Kerberos tickets.
Kerberoasting Example
1. Request TGS Ticket:
- Export Ticket:
Usekerberos::list /exportto save the ticket to a file for offline cracking.
AS-REP Roasting Example
AS-REP roasting targets accounts with NTLM authentication enabled. Use:
AS-REP format, which can be cracked with tools like Hashcat.
Key takeaways¶
- CrackMapExec automates Kerberoasting by requesting TGS tickets and exporting hashes.
- Impacket tools like
GetUserSPN.pyandGetTGT.pyare critical for identifying SPNs and extracting tickets. - Mimikatz provides granular control over Kerberos tickets, enabling both Kerberoasting and AS-REP roasting.
- All tools require domain access and proper permissions to request tickets.
- Lab environments are essential for safely testing these techniques without compromising production systems.