Commit Graph
70 Commits
Author SHA1 Message Date
Lee Christensen 129c49dc4c up version 2024-02-01 14:16:30 -08:00
0xe7 63a0604df2 upped minor version 2024-01-05 14:53:15 +00:00
0xe7 4a2fc8a3d9 Merge branch 'master' into des 2023-09-01 12:06:38 +01:00
0xe7 679e992947 adding modifications to support DES attacks 2023-08-08 23:29:31 +01:00
Ceri Coburn 64114442ef Added support for requesting a TGT with a specific principal name type 2023-08-08 13:37:14 +01:00
0xe7 9489a0c5a0 Merge pull request #156 from MWR-CyberSec/add-asreproast-aes-support
Added support for AS-REP Roasting with AES encryption types
2023-05-16 16:44:56 +01:00
0xe7 7293b2b3b5 Merge pull request #157 from eladshamir/asrep2kirbi
Add an asrep2kirbi action
2023-05-16 16:41:49 +01:00
Christo Erasmus 473933979d Added support for AS-REP Roasting with AES etypes
Added support for AS-REP Roasting with AES encryption types, through the
/aes flag for the asreproast module
2023-05-15 14:38:50 +02:00
0xe7 3cea8317bd small modify to tgssub 2023-04-20 21:00:01 +01:00
Elad Shamir 9cf6c8d683 Add an asrep2kirbi action 2023-04-18 20:09:58 +00:00
0xe7 51f1863f5d Bump version number 2023-02-03 15:20:42 +00:00
JoeDibley 6b62732efa Update Help for KeyList Requests
Updated the Info.cs and README.md to include new KeyList Request options
2023-02-01 11:37:29 +00:00
0xe7 39a3b88d92 several changes but mainly to add support for the new FullPacChecksum signature 2022-11-19 01:08:30 +00:00
CCob 52faf3b4e6 Embed Requestor SID and Attributes PAC by default
During the October 2022 update Microsoft has switched to enforcement mode for the presence of the Requestor SID and Attributes PAC as part of CVE-2021-42287, therefore default golden tickets no longer work.  Switch the behavior so that this is now default which can then be excluded using /oldpac argument
2022-11-08 09:23:17 +00:00
0xe7 c777771e55 added preauthscan command, various arguments to asktgt/kerberoast without preauth from the AS 2022-09-27 10:53:33 +01:00
4ndr3w6 82cca04a27 Version bump to 2.1.2 2022-08-09 16:15:05 -05:00
0xe7 e2b77dcab1 Merge branch 'master' into master 2022-07-05 23:44:01 +01:00
4ndr3w6S b4718685e7 upload of initial 'diamond' command 2022-07-05 01:23:34 +00:00
HarmJ0y 9544b7d7b8 Added /luid:X target to "logonsession" command
-Added /luid:X target to "logonsession" command
-Updated README
2022-06-15 06:50:03 -07:00
HarmJ0y 8c6b0017af Renamed command
-Renamed "currentlogonsession" to "logonsession"
-Added enumeration of all logonsession information if elevated
2022-06-15 06:08:36 -07:00
HarmJ0y f7f4c6bb92 Added "currentlogonsession" command
Added "currentlogonsession" command
2022-06-15 02:18:47 -07:00
HarmJ0y d2b57273ef Added /debug option
Added /debug option for ASN.1 troubleshooting
2022-05-11 14:57:03 -07:00
Charlie Clark 899743997a added support for KDC proxies to asktgt, asktgs and s4u 2022-01-27 23:40:33 +00:00
JoeDibley cfdb1c28c3 Added oldsam parameter to Asktgt
Added the /oldsam parameter to asktgt so it is possible to create AES encrypted TGT tickets when performing samaccountname spoofing from CVE-2021-42278.
2021-12-17 17:45:45 +00:00
Will aa4f6eadba Merge pull request #105 from GhostPack/pac
added support for the new info_pac_buffers and the ability to request…
2021-12-13 10:52:18 -08:00
Charlie Clark cfdff00631 added support for the new info_pac_buffers and the ability to request initial TGTs without a PAC 2021-11-19 03:07:35 +00:00
l0ss 4a7cca31d3 added option for user-defined creds in createnetonly command 2021-08-04 22:49:20 +08:00
Charlie Clark 3d85b7d1c5 changed /lastlogoff to /logofftime for golden and silver, updated CHANGELOG.md and README.md 2021-08-02 22:39:42 +01:00
Charlie Clark 207499494f aliased brute to spray 2021-07-29 10:39:30 +01:00
Charlie Clark 945e1f1091 updated documentation, made some small fixes 2021-07-29 03:29:38 +01:00
Charlie Clark d798cf7cda fixed TicketChecksum support and the other AuthorizationData elements 2021-06-08 22:50:24 +01:00
Charlie Clark c4a272baf9 added golden command and fixed EncTicketPart to use DateTimeUtcNow 2021-05-27 15:32:38 +01:00
0xe7 54e0604b04 added support for /tgs: for the asktgs command and a /usesvcdomain switch for cross domain support when using /tgs: 2021-05-14 02:03:25 +01:00
HarmJ0y 1b9d0d3f49 Replace README info
-Replace README info
-Added /verifycerts
2021-03-26 16:45:53 -07:00
HarmJ0y 0c7e522edb Version 1.6.2
-Integrated @RiccardoAncarani's PR for `/delay` and `/jitter` in `kerberoast`
-arguments can now use `/arg=value` form in addition to `/arg:value`
-few kerberoasting fixes
2021-03-12 09:45:00 -08:00
Will 753ff346fd Merge pull request #73 from 0xe7/CVE-2020-17049
CVE-2020-17049 support
2020-12-10 10:34:10 -08:00
0xe7 d3180f752f updating documentation with /bronzebit switch and changed BuildTicket to ForgeTicket 2020-12-10 16:42:57 +00:00
0xe7 819d3f4e3e included initial support for basic silver tickets, without a PAC 2020-12-10 02:30:23 +00:00
0xe7 2b6c4ebaa7 bumping the build version number in Info.cs 2020-12-07 15:52:29 +00:00
0xe7 2cbd4233da fixed cross domain enterprise princiapl kerberoasting, fixed kerberoastring using the DC IP and supplying a TGT (by resolving the IP to a name for the LDAP service ticket) and added a /autoenterprise flag to automate retrying failed kerberoasting attempts 2020-12-04 00:33:28 +00:00
harmj0y a354f6451e Updated version and changelog
Updated version and changelog
2020-11-06 12:57:30 -08:00
0xe7 f2fb7d51dc updated Info.cs usage information with the new arguments and switches 2020-11-05 23:32:58 +00:00
G0ldenGun 36165c8d83 Added runfor flag
Added runfor flag to the monitor & harvest commands.  When set, Rubeus will gracefully exit after the given length of time.  Useful when attempting to collect tickets over a non-interactive session, as captured tickets will be displayed upon exit.
2020-05-19 08:30:00 -05:00
harmj0y e52cb87a58 Version 1.5.0
-Added universal '/nowrap' flag to prevent base64-blobs from being line wrapped
-Added '/consoleoutfile' to output console output to a file
-Added public 'MainString("command")' function to invoke over PSRemoting
-"brute" action to perform password bruteforcing attacks using raw AS-REQs (from @Zer1t0)
-Standardized "/user","/LUID","/service","/server" targeting to triage/klist/dump actions
-Added to the "kerberoast" action:
    -"/pwdsetafter", "/pwdsetbefore", and "/resultlimit" arguments for better targeting (from @pkb1s)
    -"/stats" flag to list statistics of user accounts without actually roasting them
    -"/ldapfilter" argument for adding custom LDAP filters to the user search query
    -"/simple" argument for output file formatting but to the console
-Added "/ldapfilter" argument to the "asreproast" actions
-Added to the "asktgt"/"asktgs"/"s4u" actions the option to save the .kirbi file to disk (from @audrummer15)
-Added a "currentluid" command to display the current logon sesion ID
-Cross-domain s4u functionality (from @0xe7)
-Overhauled LSA.cs for reusability and flexibility (thanks for the help @leechristensen !)
-"kerberoast" action updated to exclude disabled accounts by default
-"harvest" mode's "/interval" argument is now in seconds, to match "/monitor"
-"harvest/"monitor" revamped to no longer depend on 4624 events, does full extraction on each round
-Fixed some timestamp converting code in the ticket extraction section
-KERB_RETRIEVE_TKT_REQUEST fix for x32 systems (from @0xRCA)
-Fixed AES salt generation (from @monoxgas)
-Fixed accidental ticket request behavior when dumping from LsaCallAuthenticationPackage
-Fixed "renew" command invocation
-Fixed "asreproast" LDAP querying
2020-01-31 13:14:24 -08:00
audrummer15 6ed118ffa0 * Add option to save TGS tickets when using s4u commands 2019-09-17 17:03:43 -04:00
audrummer15 d7eb34bd71 * Add option to save TGT to disk when using renew command 2019-09-14 01:10:17 -04:00
audrummer15 930c484fd2 * Add option to save TGS to disk when using AskTGS 2019-09-14 00:58:28 -04:00
audrummer15 cfdf3e7ae5 * Add option to save TGT to disk when using AskTGT 2019-09-14 00:06:16 -04:00
Will 9252f98c80 Merge pull request #26 from pkb1s/master
Adding 3 new options to the kerberoast command
2019-09-05 12:07:18 -07:00
pkb1s c63a1e4c39 Update Info.cs 2019-06-13 20:43:53 +01:00