Expand description
Kerberos roasting layer.
LDAP finds the candidates (SPN → Kerberoast, DONT_REQ_PREAUTH → AS-REP roast).
This crate turns an AS-REP-roastable account into a crackable hash by sending a raw
pre-auth-less AS-REQ to the KDC (messages built on picky-krb) and formatting the
reply for hashcat. AS-REP roasting needs no credentials, so it is implemented in
full and end-to-end. Kerberoast (TGS-REQ) needs a TGT — see the note on kerberoast.
Modules§
- csr
- PKCS#10 certificate-signing request (RFC 2986) with an optional UPN
otherNameSAN — the ESC1 abuse primitive: on an enrollee-supplies-subject template the CA honors this SAN, so a CSR carryingotherName=Administrator@realmyields a client-auth cert usable to PKINIT as that user. Hand-rolled DER (signed SHA-256/RSA) so it stays on the existingrsadep. - gss
- Minimal GSS-API / SPNEGO framing for a Kerberos AP-REQ carried in an SMB2 SESSION_SETUP.
- pac
- PAC (MS-PAC) marshaling adapter — the bulk of this module lives in the
standalone
ms-pac-forgecrate; here we just re-export it and layer the adhammer-specificdecrypt_ticket_pacon top of picky-krb’sTgt. - pkinit
- Shadow Credentials Phase 2 — PKINIT authentication.
- rc4
- RC4-HMAC (etype 23, RFC 4757 / MS-KILE) — re-exports over
ms_pac_forge::checksum. - shadowcred
- Shadow Credentials (MS-ADTS msDS-KeyCredentialLink) — Phase 1: build a KeyCredential from a fresh RSA key and format it as the DN-Binary value to write to a target we can write. Phase 2 (PKINIT auth with the key) is separate. AD validates the blob structure on write, so a successful write confirms the structure is correct.
- unpac
- 1.4.8-A WS-UNPAC-PKINIT — unPAC-the-hash: extract the NT hash of an
impersonated principal out of a PAC’s
PAC_CREDENTIAL_INFO(ulType=2) buffer.
Structs§
- Candidate
- A roastable principal discovered from the snapshot.
- Service
Ticket - A service ticket plus its session key — the material for a Kerberos AP-REQ (pass-the-ticket).
- Tgt
- Ticket-Granting Ticket plus the material needed to use it.
- Ticket
Timestamps - 1.4.8-A WS-DIAMOND-TICKET: overrides for a forged ticket’s timestamps.
Noneon any field falls back tonow_kerberos_time()/far_future_time()(the Golden / Silver default that flags anomalously — 10-year validity is a well-known IOC). A Diamond ticket populates all four from a legitimately-obtained TGT so the forged one’s clock-domain matches the KDC exactly.
Enums§
- Cred
Result - Outcome of a Kerberos pre-auth credential check (password spray / user enum).
- Kerbrute
Outcome - Result of a
kerbrute_probecall. See variant docs for the KDC error-code mapping.
Constants§
- ETYPE_
AES128 - ETYPE_
AES256 - ETYPE_
RC4_ HMAC - Kerberos encryption type numbers (RFC 3961/4120).
Functions§
- asktgt
- Ask-TGT: obtain a TGT with a password (AES256 first, with ETYPE-INFO2 salt discovery) and emit
a reusable MIT ccache for Kerberos-only (
-k) workflows. If the account has no AES key (the KDC answers ETYPE_NOSUPP) — e.g. the built-in Administrator whose password was set before the domain existed, or an RC4-only account — it transparently falls back to an RC4-HMAC TGT from the NT hash. - asrep_
roast - build_
ap_ req_ gss - Build the GSS/SPNEGO AP-REQ blob for an SMB2 SESSION_SETUP from a
ServiceTicket, and return it together with the 16-byte SMB session key. The authenticator carries a random AES128 subkey (etype 17) which becomes the GSS/SMB session key, so SMB signing is deterministic on our side. - build_
ap_ req_ gss_ aes256 - AES256 variant of
build_ap_req_gss— generates a 32-byte AES256 subkey (etype 18) and returns the RAW GSS-Kerberos token (not SPNEGO-wrapped) plus the subkey. - candidates
- Enumerate roasting candidates from LDAP data — no network.
- check_
credential - Validate one credential via a Kerberos AS pre-auth exchange (no LDAP needed). The KDC error code classifies the result — the basis for password spraying and user enumeration.
- forge_
diamond_ tgt - 1.4.8-A WS-DIAMOND-TICKET: forge a Diamond ticket — a TGT with an
attacker-chosen PAC (
id_overrides) but timestamps +cnameinherited from a legitimately-obtained real TGT (real). The outer TGT looks like a normal KDC-issued ticket (real auth/start/end/renew times matching wall-clock, real principal), only the PAC’s group memberships / SIDs are attacker-controlled. - forge_
golden_ tgt - Forge a golden ticket: a TGT for an arbitrary identity, its EncTicketPart (with a forged PAC)
sealed under the domain’s krbtgt AES256 key. The PAC’s server and KDC signatures are both
computed with the krbtgt key, so a fully-patched (KB5020805) KDC accepts it. Returns a usable
Tgt; feed it toroast_spnfor a live acceptance proof orgolden_ccacheto persist. - forge_
silver_ tgt - Forge a silver ticket: a service ticket (TGS) for
spn, sealed + PAC-signed under the target service account’s AES256 key (fromdcsync <machine$/svc>). Used directly against the service (AP-REQ) without contacting the KDC — so the KDC signature is unchecked; both PAC signatures use the service key. Returns the forged service ticket as aTgtwrapper (.ticket/session key); persist withsilver_ccache. - format_
asrep - hashcat
-m 18200line for an AS-REP (etype 23):$krb5asrep$23$user@REALM:<checksum16>$<edata> - format_
asrep_ aes - hashcat
-m 18200line for an AES AS-REP (etype 17/18):$krb5asrep$<etype>$user@REALM:<checksum12>$<edata>(AES puts the 12-byte HMAC last; hashcat wants checksum-then-edata, matching the AES TGS format). - format_
tgs - hashcat
-m 13100line for an RC4 TGS-REP (etype 23):$krb5tgs$23$*user$REALM$spn*$<checksum16>$<edata>(RC4 puts the 16-byte checksum first). - format_
tgs_ aes - hashcat
-m 19600(AES128, etype 17) /-m 19700(AES256, etype 18) TGS line:$krb5tgs$<etype>$*user$REALM$spn*$<checksum12>$<edata>(AES puts the 12-byte HMAC last). - get_
service_ ticket - TGS-REQ for
spnusing a TGT (real or forged golden), requesting an AES256 service ticket, and decrypt the reply enc-part with the TGT session key (usage 8) to recover the new service session key. The returnedServiceTicketdrives a Kerberos SMB/LDAP AP-REQ. - get_tgt
- AS-REP roast a TGT via the two-step AS exchange: first an un-authenticated AS-REQ to learn the real salt (ETYPE-INFO2), then an AS-REQ with PA-ENC-TIMESTAMP.
- get_
tgt_ by_ hash - Stream 5 / A.7: obtain a live
Tgt(session key + ticket) from just an NT hash — the in-memory counterpart tooverpass_the_hash, which returns a serialized ccache. Used byattack rbcd --nt-hashand any callsite that needs to fold an S4U/TGS chain on top of a pass-the-hash TGT without a temporary ccache round-trip. Same wire behaviour: single AS-REQ with PA-ENC-TIMESTAMP encrypted under RC4-HMAC (the NT hash is the Kerberos key). - golden_
ccache - Serialize a forged
Tgtto an MIT credential cache (usable withKRB5CCNAME/-ktools). - kerbrute_
probe - 1.4.8-A WS-KERBRUTE: probe one username against the KDC without pre-auth,
classify the response. Kerberos leaks user existence via its error codes — a
user that exists rejects with
KDC_ERR_PREAUTH_REQUIRED(25) or (if account hasDONT_REQ_PREAUTH) succeeds and returns an AS-REP; an unknown principal rejects withKDC_ERR_C_PRINCIPAL_UNKNOWN(6). This is the primitiveKerbruteet al. wrap; no LDAP creds needed. - name_
asrep_ krb_ error - Perform an AS-REP roast against one candidate; returns the hashcat 18200 line.
No credentials required — relies on the account’s DONT_REQ_PREAUTH flag.
Map a KRB-ERROR
error_codevalue (RFC 4120 §7.5.9) to a one-line operator-facing name + hint, orNonefor codes we don’t yet special-case. Extracted fromasrep_roastso 1.5.2 UX-D carries a unit test seeded from the exact codes testlab.local returned during the live-fire (code 23 =KDC_ERR_KEY_EXPIREDonroastme). - overpass_
the_ hash - Overpass-the-hash: obtain a TGT from just an NT hash via RC4-HMAC (etype 23) — the legacy (RC4-enabled, Server ≤2022) path. No salt discovery needed: the RC4 Kerberos key is the NT hash, so a captured/pass-the-hash NT hash becomes a full Kerberos TGT (ccache).
- rbcd_
impersonate - Full RBCD chain: TGT for the controlled account → S4U2Self(impersonate) → S4U2Proxy to the target service. Returns the etype of the final impersonation ticket as proof.
- rbcd_
impersonate_ by_ hash - Stream 5 / A.7: pass-the-hash variant of
rbcd_impersonate. The trustee account is often a captured computer object where only the NT (RC4) hash is known — this path builds the TGT from the hash and runs the same S4U2Self/S4U2Proxy chain. Returns the enc-part etype of the final impersonation ticket. - roast_
spn - Build a TGS-REQ for
spnusing the TGT, and return the crackable service-ticket hash. - silver_
ccache - Serialize a forged silver ticket to a ccache (server principal = the SPN).
- silver_
service_ ticket - Wrap a forged silver ticket (
forge_silver_tgt) as aServiceTicketfor AP-REQ — no KDC round-trip; the session key is the one embedded when forging.