Skip to main content

Crate adhammer_kerberos

Crate adhammer_kerberos 

Source
Expand description

Kerberos roasting layer.

LDAP finds the candidates (SPN → Kerberoast, DONT_REQ_PREAUTH → AS-REP roast). This crate turns an AS-REP-roastable account into a crackable hash by sending a raw pre-auth-less AS-REQ to the KDC (messages built on picky-krb) and formatting the reply for hashcat. AS-REP roasting needs no credentials, so it is implemented in full and end-to-end. Kerberoast (TGS-REQ) needs a TGT — see the note on kerberoast.

Modules§

csr
PKCS#10 certificate-signing request (RFC 2986) with an optional UPN otherName SAN — the ESC1 abuse primitive: on an enrollee-supplies-subject template the CA honors this SAN, so a CSR carrying otherName=Administrator@realm yields a client-auth cert usable to PKINIT as that user. Hand-rolled DER (signed SHA-256/RSA) so it stays on the existing rsa dep.
gss
Minimal GSS-API / SPNEGO framing for a Kerberos AP-REQ carried in an SMB2 SESSION_SETUP.
pac
PAC (MS-PAC) marshaling adapter — the bulk of this module lives in the standalone ms-pac-forge crate; here we just re-export it and layer the adhammer-specific decrypt_ticket_pac on top of picky-krb’s Tgt.
pkinit
Shadow Credentials Phase 2 — PKINIT authentication.
rc4
RC4-HMAC (etype 23, RFC 4757 / MS-KILE) — re-exports over ms_pac_forge::checksum.
shadowcred
Shadow Credentials (MS-ADTS msDS-KeyCredentialLink) — Phase 1: build a KeyCredential from a fresh RSA key and format it as the DN-Binary value to write to a target we can write. Phase 2 (PKINIT auth with the key) is separate. AD validates the blob structure on write, so a successful write confirms the structure is correct.
unpac
1.4.8-A WS-UNPAC-PKINIT — unPAC-the-hash: extract the NT hash of an impersonated principal out of a PAC’s PAC_CREDENTIAL_INFO (ulType=2) buffer.

Structs§

Candidate
A roastable principal discovered from the snapshot.
ServiceTicket
A service ticket plus its session key — the material for a Kerberos AP-REQ (pass-the-ticket).
Tgt
Ticket-Granting Ticket plus the material needed to use it.
TicketTimestamps
1.4.8-A WS-DIAMOND-TICKET: overrides for a forged ticket’s timestamps. None on any field falls back to now_kerberos_time() / far_future_time() (the Golden / Silver default that flags anomalously — 10-year validity is a well-known IOC). A Diamond ticket populates all four from a legitimately-obtained TGT so the forged one’s clock-domain matches the KDC exactly.

Enums§

CredResult
Outcome of a Kerberos pre-auth credential check (password spray / user enum).
KerbruteOutcome
Result of a kerbrute_probe call. See variant docs for the KDC error-code mapping.

Constants§

ETYPE_AES128
ETYPE_AES256
ETYPE_RC4_HMAC
Kerberos encryption type numbers (RFC 3961/4120).

Functions§

asktgt
Ask-TGT: obtain a TGT with a password (AES256 first, with ETYPE-INFO2 salt discovery) and emit a reusable MIT ccache for Kerberos-only (-k) workflows. If the account has no AES key (the KDC answers ETYPE_NOSUPP) — e.g. the built-in Administrator whose password was set before the domain existed, or an RC4-only account — it transparently falls back to an RC4-HMAC TGT from the NT hash.
asrep_roast
build_ap_req_gss
Build the GSS/SPNEGO AP-REQ blob for an SMB2 SESSION_SETUP from a ServiceTicket, and return it together with the 16-byte SMB session key. The authenticator carries a random AES128 subkey (etype 17) which becomes the GSS/SMB session key, so SMB signing is deterministic on our side.
build_ap_req_gss_aes256
AES256 variant of build_ap_req_gss — generates a 32-byte AES256 subkey (etype 18) and returns the RAW GSS-Kerberos token (not SPNEGO-wrapped) plus the subkey.
candidates
Enumerate roasting candidates from LDAP data — no network.
check_credential
Validate one credential via a Kerberos AS pre-auth exchange (no LDAP needed). The KDC error code classifies the result — the basis for password spraying and user enumeration.
forge_diamond_tgt
1.4.8-A WS-DIAMOND-TICKET: forge a Diamond ticket — a TGT with an attacker-chosen PAC (id_overrides) but timestamps + cname inherited from a legitimately-obtained real TGT (real). The outer TGT looks like a normal KDC-issued ticket (real auth/start/end/renew times matching wall-clock, real principal), only the PAC’s group memberships / SIDs are attacker-controlled.
forge_golden_tgt
Forge a golden ticket: a TGT for an arbitrary identity, its EncTicketPart (with a forged PAC) sealed under the domain’s krbtgt AES256 key. The PAC’s server and KDC signatures are both computed with the krbtgt key, so a fully-patched (KB5020805) KDC accepts it. Returns a usable Tgt; feed it to roast_spn for a live acceptance proof or golden_ccache to persist.
forge_silver_tgt
Forge a silver ticket: a service ticket (TGS) for spn, sealed + PAC-signed under the target service account’s AES256 key (from dcsync <machine$/svc>). Used directly against the service (AP-REQ) without contacting the KDC — so the KDC signature is unchecked; both PAC signatures use the service key. Returns the forged service ticket as a Tgt wrapper (.ticket/session key); persist with silver_ccache.
format_asrep
hashcat -m 18200 line for an AS-REP (etype 23): $krb5asrep$23$user@REALM:<checksum16>$<edata>
format_asrep_aes
hashcat -m 18200 line for an AES AS-REP (etype 17/18): $krb5asrep$<etype>$user@REALM:<checksum12>$<edata> (AES puts the 12-byte HMAC last; hashcat wants checksum-then-edata, matching the AES TGS format).
format_tgs
hashcat -m 13100 line for an RC4 TGS-REP (etype 23): $krb5tgs$23$*user$REALM$spn*$<checksum16>$<edata> (RC4 puts the 16-byte checksum first).
format_tgs_aes
hashcat -m 19600 (AES128, etype 17) / -m 19700 (AES256, etype 18) TGS line: $krb5tgs$<etype>$*user$REALM$spn*$<checksum12>$<edata> (AES puts the 12-byte HMAC last).
get_service_ticket
TGS-REQ for spn using a TGT (real or forged golden), requesting an AES256 service ticket, and decrypt the reply enc-part with the TGT session key (usage 8) to recover the new service session key. The returned ServiceTicket drives a Kerberos SMB/LDAP AP-REQ.
get_tgt
AS-REP roast a TGT via the two-step AS exchange: first an un-authenticated AS-REQ to learn the real salt (ETYPE-INFO2), then an AS-REQ with PA-ENC-TIMESTAMP.
get_tgt_by_hash
Stream 5 / A.7: obtain a live Tgt (session key + ticket) from just an NT hash — the in-memory counterpart to overpass_the_hash, which returns a serialized ccache. Used by attack rbcd --nt-hash and any callsite that needs to fold an S4U/TGS chain on top of a pass-the-hash TGT without a temporary ccache round-trip. Same wire behaviour: single AS-REQ with PA-ENC-TIMESTAMP encrypted under RC4-HMAC (the NT hash is the Kerberos key).
golden_ccache
Serialize a forged Tgt to an MIT credential cache (usable with KRB5CCNAME / -k tools).
kerbrute_probe
1.4.8-A WS-KERBRUTE: probe one username against the KDC without pre-auth, classify the response. Kerberos leaks user existence via its error codes — a user that exists rejects with KDC_ERR_PREAUTH_REQUIRED (25) or (if account has DONT_REQ_PREAUTH) succeeds and returns an AS-REP; an unknown principal rejects with KDC_ERR_C_PRINCIPAL_UNKNOWN (6). This is the primitive Kerbrute et al. wrap; no LDAP creds needed.
name_asrep_krb_error
Perform an AS-REP roast against one candidate; returns the hashcat 18200 line. No credentials required — relies on the account’s DONT_REQ_PREAUTH flag. Map a KRB-ERROR error_code value (RFC 4120 §7.5.9) to a one-line operator-facing name + hint, or None for codes we don’t yet special-case. Extracted from asrep_roast so 1.5.2 UX-D carries a unit test seeded from the exact codes testlab.local returned during the live-fire (code 23 = KDC_ERR_KEY_EXPIRED on roastme).
overpass_the_hash
Overpass-the-hash: obtain a TGT from just an NT hash via RC4-HMAC (etype 23) — the legacy (RC4-enabled, Server ≤2022) path. No salt discovery needed: the RC4 Kerberos key is the NT hash, so a captured/pass-the-hash NT hash becomes a full Kerberos TGT (ccache).
rbcd_impersonate
Full RBCD chain: TGT for the controlled account → S4U2Self(impersonate) → S4U2Proxy to the target service. Returns the etype of the final impersonation ticket as proof.
rbcd_impersonate_by_hash
Stream 5 / A.7: pass-the-hash variant of rbcd_impersonate. The trustee account is often a captured computer object where only the NT (RC4) hash is known — this path builds the TGT from the hash and runs the same S4U2Self/S4U2Proxy chain. Returns the enc-part etype of the final impersonation ticket.
roast_spn
Build a TGS-REQ for spn using the TGT, and return the crackable service-ticket hash.
silver_ccache
Serialize a forged silver ticket to a ccache (server principal = the SPN).
silver_service_ticket
Wrap a forged silver ticket (forge_silver_tgt) as a ServiceTicket for AP-REQ — no KDC round-trip; the session key is the one embedded when forging.