module

Kerberos keytab utilities

Disclosed
N/A
Created
2023-01-27

Description

Utilities for interacting with keytab files, which can store the hashed passwords of one or
more principals.

Discovered keytab files can be used to generate Kerberos Ticket Granting Tickets, or bruteforced
offline.

Keytab files can be also useful for decrypting Kerberos traffic using Wireshark dissectors,
including the krbtgt encrypted blobs if the AES password hash is used.

Author

alanfoster

Module Options

To display the available options, load the module within the Metasploit console and run the commands ‘show options’ or ‘show advanced’:


msf > use auxiliary/admin/kerberos/keytab
msf auxiliary(keytab) > show actions
...actions...
msf auxiliary(keytab) > set ACTION < action-name >
msf auxiliary(keytab) > show options
...show and set options...
msf auxiliary(keytab) > run

Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.