66 Commits
Author SHA1 Message Date
Clément Notin d139d630c9 Fix minor typo "requset" 2025-04-03 02:13:37 +02:00
Ceri Coburn 5ca374f62a Add support for requesting services tickets via LSA. This is helpful on machines where credential guard is present 2025-02-25 09:30:10 +00:00
Joe afa32afc96 Support Delegated Managed Service Account Kerberos Processes (#194)
* Initial Implementation of DMSA Support. This includes KERB-DMSA-KEY-PACKAGE and KERB-SUPERSEDED-BY-USER structures and returning data.

* Remove a console output

* Help doc updates

* Ticket Display Updates so if previous keys are needed they can be added at a later date easily.

* Clean up, comments and support child domain fqdns

* Update versions

* Change output for DMSA Request to include DMSA User and the requesting user (Computer)
2025-02-01 12:32:55 +00:00
0xe7 63a0604df2 upped minor version 2024-01-05 14:53:15 +00:00
0xe7 679e992947 adding modifications to support DES attacks 2023-08-08 23:29:31 +01:00
0xe7 7293b2b3b5 Merge pull request #157 from eladshamir/asrep2kirbi
Add an asrep2kirbi action
2023-05-16 16:41:49 +01:00
0xe7 3cea8317bd small modify to tgssub 2023-04-20 21:00:01 +01:00
Elad Shamir 9cf6c8d683 Add an asrep2kirbi action 2023-04-18 20:09:58 +00:00
JoeDibley 6b62732efa Update Help for KeyList Requests
Updated the Info.cs and README.md to include new KeyList Request options
2023-02-01 11:37:29 +00:00
0xe7 39a3b88d92 several changes but mainly to add support for the new FullPacChecksum signature 2022-11-19 01:08:30 +00:00
CCob 52faf3b4e6 Embed Requestor SID and Attributes PAC by default
During the October 2022 update Microsoft has switched to enforcement mode for the presence of the Requestor SID and Attributes PAC as part of CVE-2021-42287, therefore default golden tickets no longer work.  Switch the behavior so that this is now default which can then be excluded using /oldpac argument
2022-11-08 09:23:17 +00:00
0xe7 c777771e55 added preauthscan command, various arguments to asktgt/kerberoast without preauth from the AS 2022-09-27 10:53:33 +01:00
0xe7 e2b77dcab1 Merge branch 'master' into master 2022-07-05 23:44:01 +01:00
4ndr3w6S b4718685e7 upload of initial 'diamond' command 2022-07-05 01:23:34 +00:00
HarmJ0y 9544b7d7b8 Added /luid:X target to "logonsession" command
-Added /luid:X target to "logonsession" command
-Updated README
2022-06-15 06:50:03 -07:00
HarmJ0y f7f4c6bb92 Added "currentlogonsession" command
Added "currentlogonsession" command
2022-06-15 02:18:47 -07:00
HarmJ0y d2b57273ef Added /debug option
Added /debug option for ASN.1 troubleshooting
2022-05-11 14:57:03 -07:00
0xe7 d3eea5d2d0 Merge branch 'master' into master 2022-03-08 11:32:40 +00:00
James Forshaw 36ef496889 Added createnetonly parameter to S4U. 2022-01-29 00:06:35 -08:00
Charlie Clark 899743997a added support for KDC proxies to asktgt, asktgs and s4u 2022-01-27 23:40:33 +00:00
Charlie Clark cfdff00631 added support for the new info_pac_buffers and the ability to request initial TGTs without a PAC 2021-11-19 03:07:35 +00:00
CCob 3990ca582f Add support for changing passwords of expired accounts. 2021-08-12 10:47:42 +01:00
CCob 44312f0f2f Update README.md 2021-08-03 18:22:55 +01:00
Charlie Clark 3d85b7d1c5 changed /lastlogoff to /logofftime for golden and silver, updated CHANGELOG.md and README.md 2021-08-02 22:39:42 +01:00
Charlie Clark 095ef5398d fix readme 2021-07-29 10:55:34 +01:00
Charlie Clark 207499494f aliased brute to spray 2021-07-29 10:39:30 +01:00
Charlie Clark 945e1f1091 updated documentation, made some small fixes 2021-07-29 03:29:38 +01:00
0xe7 d4e00a78a8 fixed typo in README 2021-05-14 02:07:07 +01:00
0xe7 54e0604b04 added support for /tgs: for the asktgs command and a /usesvcdomain switch for cross domain support when using /tgs: 2021-05-14 02:03:25 +01:00
HarmJ0y 1b9d0d3f49 Replace README info
-Replace README info
-Added /verifycerts
2021-03-26 16:45:53 -07:00
HarmJ0y 0c7e522edb Version 1.6.2
-Integrated @RiccardoAncarani's PR for `/delay` and `/jitter` in `kerberoast`
-arguments can now use `/arg=value` form in addition to `/arg:value`
-few kerberoasting fixes
2021-03-12 09:45:00 -08:00
harmj0y 89c0bf6b07 Updated README.md
-Updated command line usage
-Added monitor/harvest /runfor documentation
2021-01-25 16:20:05 -08:00
Will 753ff346fd Merge pull request #73 from 0xe7/CVE-2020-17049
CVE-2020-17049 support
2020-12-10 10:34:10 -08:00
0xe7 d3180f752f updating documentation with /bronzebit switch and changed BuildTicket to ForgeTicket 2020-12-10 16:42:57 +00:00
0xe7 2cbd4233da fixed cross domain enterprise princiapl kerberoasting, fixed kerberoastring using the DC IP and supplying a TGT (by resolving the IP to a name for the LDAP service ticket) and added a /autoenterprise flag to automate retrying failed kerberoasting attempts 2020-12-04 00:33:28 +00:00
0xe7 09c533edf6 modified README.md to including information about the various PR's I've done 2020-10-30 11:15:33 +00:00
Will 2d5e977cd0 Typo fixes 2020-10-03 10:42:12 -07:00
harmj0y f1138ddadf Updated README.md
Updated with additional thanks and citations
2020-10-02 14:57:49 -07:00
CCob 3746efd67d Initial support for PKINIT TGT's 2020-09-27 12:38:54 +01:00
harmj0y fac7010467 Updated documentation to fix issue #55
Updated documentation to fix issue #55 about Visual Studio versioning.
2020-08-18 10:36:41 -07:00
r3motecontrol 652babce42 missing parenthesis in readme.md 2020-06-06 19:13:57 -04:00
harmj0y e52cb87a58 Version 1.5.0
-Added universal '/nowrap' flag to prevent base64-blobs from being line wrapped
-Added '/consoleoutfile' to output console output to a file
-Added public 'MainString("command")' function to invoke over PSRemoting
-"brute" action to perform password bruteforcing attacks using raw AS-REQs (from @Zer1t0)
-Standardized "/user","/LUID","/service","/server" targeting to triage/klist/dump actions
-Added to the "kerberoast" action:
    -"/pwdsetafter", "/pwdsetbefore", and "/resultlimit" arguments for better targeting (from @pkb1s)
    -"/stats" flag to list statistics of user accounts without actually roasting them
    -"/ldapfilter" argument for adding custom LDAP filters to the user search query
    -"/simple" argument for output file formatting but to the console
-Added "/ldapfilter" argument to the "asreproast" actions
-Added to the "asktgt"/"asktgs"/"s4u" actions the option to save the .kirbi file to disk (from @audrummer15)
-Added a "currentluid" command to display the current logon sesion ID
-Cross-domain s4u functionality (from @0xe7)
-Overhauled LSA.cs for reusability and flexibility (thanks for the help @leechristensen !)
-"kerberoast" action updated to exclude disabled accounts by default
-"harvest" mode's "/interval" argument is now in seconds, to match "/monitor"
-"harvest/"monitor" revamped to no longer depend on 4624 events, does full extraction on each round
-Fixed some timestamp converting code in the ticket extraction section
-KERB_RETRIEVE_TKT_REQUEST fix for x32 systems (from @0xRCA)
-Fixed AES salt generation (from @monoxgas)
-Fixed accidental ticket request behavior when dumping from LsaCallAuthenticationPackage
-Fixed "renew" command invocation
-Fixed "asreproast" LDAP querying
2020-01-31 13:14:24 -08:00
Will 9252f98c80 Merge pull request #26 from pkb1s/master
Adding 3 new options to the kerberoast command
2019-09-05 12:07:18 -07:00
pkb1s e65377735c Update README.md 2019-06-13 20:43:21 +01:00
pkb1s 6e7b4d2b53 Update README.md 2019-06-13 19:57:32 +01:00
Zer1t0 ec944095f8 added usage with brute to README 2019-03-15 07:40:53 +01:00
HarmJ0y ab2ae64f38 Version 1.4.2
-tgs sname substitution for @eladshamir :)
2019-03-01 13:03:39 -08:00
HarmJ0y 7b77198664 Version 1.4.1
-Added /enctype to the "asktgs" command to force a particular etype
-Various output formatting tweaks
2019-02-25 15:16:01 -08:00
HarmJ0y 1155140b15 Version 1.4.0
-added "hash" command to hash password to des/rc4/aes128/aes256 forms
-fixed default Kerberoast LDAP query
-Added des/aes128 /enctype support for "asktgt"
-replaced hashing crypto code with KERB_ECRYPT HassPassword() approach a la Mimikatz
-added @elad_shamir to references in readme
2019-02-16 19:08:39 -08:00
HarmJ0y 08afa9ecf4 Version 1.3.6
-/aes and /rc4opsec commands for *kerberoast*
-*kerberoast* /tgtdeleg requests RC4 for AES enabled accounts
-EType display in *kerberoast* output

See CHANGELOG.md for complete changes
2019-02-14 18:04:33 -08:00