Active Directory
Rubeus
C# toolset for Kerberos abuse (AS-REP, kerberoast, tickets, etc.).
Authorized testing only. Practice on systems you own, isolated labs, or targets with written permission. Unauthorized access is illegal.
When
Windows host access in domain environments for Kerberos attacks.
How
Run from beacon/session; roast, request TGTs, pass tickets.
Why
Kerberos is the heart of AD authentication abuse.
Commands & usage
Rubeus.exe kerberoast /outfile:hashes.txt
Rubeus.exe asreproast /format:hashcat
Rubeus.exe triage
Commands are educational examples. Adapt hosts, paths, and rates to your authorized scope.
Tags
Related in Active Directory
Impacket
Python collection for Windows network protocols (SMB, WMI, Kerberos, etc.).
CrackMapExec / NetExec
Swiss army knife for pentesting Windows/Active Directory networks (NetExec successor).
BloodHound / SharpHound / AzureHound
Maps Active Directory attack paths using graph theory.
enum4linux-ng
SMB/Windows enumeration tool wrapping common Samba tools.
SMBMap
Enumerates Samba share drives across networks with permissions.
ldapsearch / windapsearch
Query LDAP/Active Directory directory data.