LogoAwesome Skills
  • Search
  • Category
  • Tag
  • Blog
LogoAwesome Skills
LogoAwesome Skills

Discover Open-Source Agent Skills for AI Coding Assistants

Product

  • Search
  • Category
  • Tag
  • Blog

Resources

  • Claude Skill Docs
  • Antigravity Skills Docs

Tools

  • Claude Code
  • OpenCode
  • Cursor
  • Codex
  • Antigravity

Company

  • Privacy Policy
  • Terms of Service
  • Sitemap

©2026 Awesome Skills. All rights reserved.

Privacy PolicyTerms
Back to Skills

active-directory-kerberos-attacks

Kerberos attack playbook for Active Directory. Use when targeting AD authentication via AS-REP roasting, Kerberoasting, golden/silver/diamond tickets, delegation abuse, or pass-the-ticket attacks.

1,297stars177forksUpdated 7/7/2026
Security#security#active-directory#penetration-testing#red-team#kerberos

Security Assessment

Safe(100/100)
Security Score100/100

About active-directory-kerberos-attacks

Kerberos Attack Playbook is a security-testing reference covering the major techniques for abusing Kerberos authentication in Active Directory environments. Written for penetration testers and red teams, it begins with a primer on the Kerberos AS-REQ/AS-REP and TGS-REQ/TGS-REP message flow, then works through credential-access and impersonation techniques with concrete tool commands.

The credential-harvesting sections cover AS-REP roasting (querying users who do not require Kerberos pre-authentication and cracking the returned hashes) and Kerberoasting (any domain user can request service tickets for accounts with SPNs and crack them offline). Enumeration and request commands are given for Impacket (GetNPUsers, GetUserSPNs), Rubeus, and PowerView, with hashcat modes (18200 for AS-REP, 13100 and 19700 for TGS) and John for cracking. The ticket-forging section distinguishes golden tickets (forged TGTs signed with the krbtgt hash), silver tickets (forged service tickets using a service account hash, with no KDC interaction), and the harder-to-detect diamond and sapphire variants that modify or reuse genuine PAC data. Delegation abuse is covered across unconstrained delegation, constrained delegation via S4U2Proxy, and resource-based constrained delegation (RBCD), followed by pass-the-ticket and overpass-the-hash.

Use it when an engagement targets AD authentication and you need the prerequisites, commands, and trade-offs for a specific technique, for instance knowing that a golden ticket requires the krbtgt NTLM hash and stays valid until that password is changed twice, or that RC4 service tickets crack far faster than AES256. The playbook notes that base models frequently blur ticket-type distinctions, delegation-chain nuances, and detection-evasion trade-offs, and it routes to related playbooks for ACL abuse, AD Certificate Services, NTLM relay, and lateral movement, plus an attack-chain reference for end-to-end scenarios from foothold to domain admin.

FAQ

What attacks does this cover?

AS-REP roasting, Kerberoasting, golden/silver/diamond/sapphire ticket forging, delegation abuse (unconstrained, constrained via S4U2Proxy, and resource-based), pass-the-ticket, and overpass-the-hash.

What is the difference between a golden and a silver ticket?

A golden ticket forges a TGT signed with the krbtgt hash to impersonate any user, while a silver ticket forges a service ticket (TGS) using a specific service account's hash to access one service with no KDC interaction.

What tools are referenced?

Impacket (GetNPUsers, GetUserSPNs, ticketer, getST, addcomputer, rbcd, psexec), Rubeus, Mimikatz, and PowerView for the attacks, plus hashcat and John for cracking.

What do you need to forge a golden ticket?

The krbtgt account's NTLM hash, obtained from DCSync or NTDS.dit. A golden ticket remains valid until the krbtgt password is changed twice.

Which hashcat modes crack the captured hashes?

Mode 18200 for AS-REP roasting hashes, and mode 13100 (RC4) or 19700 (AES) for Kerberoast service tickets; RC4 tickets crack much faster than AES256.

All Files

2 files
KERBEROS_ATTACK_CHAINS.md6.8 KB
View
SKILL.md10.0 KB
View

Install active-directory-kerberos-attacks

Download and extract the skill files to your .claude/skills/ directory.

Quick Setup:

  1. Copy the skill folder to .claude/skills/
  2. Claude will automatically detect and use the skill

Repository

yaklang/hack-skills

Related Skills

referral-program

2,132

agentmail-cli

22

codex

3,038

content-modeling

192