Roasting
Last updated
Last updated
From Windows Shell
PowerShell One-Liner
Downloads Invoke-Kerberoast.ps1 from Kali, executes it, and saves output to file for hashcat reversing
Rubeus
Mimikatz
No pass or admin required:
From Kali
No Passwords, Known-Good Users
With Full Creds
More Kerberos in-depth:
More rare than kerberoasting because something has to be set manually, namely the ‘no preauth required’ has to be unchecked on the account, meaning it doesn't need to use kerberos to request
or without any password!
Or from a list
If you've added to hosts file you won't need the IP written explicitly