Rubeus specializes in interactions with the Kerberos protocol, an essential component of Windows AD environments. It's designed to perform a wide range of attacks and manipulations on Kerberos tickets, positioning it as an indispensable tool for penetration testers aiming to uncover and exploit Kerberos-based vulnerabilities.
Core Features:
Installation:
You can find Rubeus on GitHub here.
You can then use your preferred .NET compiler to generate the Rubeus executable.
Rubeus comes equipped with modules designed to target specific vulnerabilities within AD, each serving a unique purpose in the AD penetration testing process. We will be looking at just a few of the many modules this tool has to offer when you find yourself in an Active Directory environment with access to a Windows host during a penetration test.
Kerberoast
Kerberoasting takes advantage of the way service accounts are implemented in Kerberos, allowing attackers to crack the passwords of those accounts by extracting hash values from Ticket Granting Service (TGS) tickets.
Rubeus.exe kerberoast /nowrap
Tip: To specify the output file, use the /outfile flag, followed by the full path of where the hashes should be written.
AS-REPRoast
AS-REP roasting exploits a feature of Kerberos where some accounts are configured not to require pre-authentication. Attackers use this feature to request authentication data for a user without providing a valid timestamp, enabling them to attempt offline cracking of the user's password.
Rubeus.exe s4u asreproast /nowrap
Tip: If you want to specify just one user to target, add the /user flag to the command above.
Monitor
The monitor module watches for Kerberos ticket requests and renewals in real time, offering immediate insights into authentication activities and identifying potential security breaches as they occur.
Rubeus.exe monitor /interval:10 /nowrap
Tip: Use your favorite authentication coercion tools to force users or computers to authenticate to your victim machine to grab additional Kerberos tickets.
Triage
Triage is used for collecting and displaying all available Kerberos tickets on a host, aiding in the identification of active user sessions and potential targets for escalation or lateral movement.
Rubeus.exe triage
Dump
Dumping Kerberos ticket data allows for the offline analysis of tickets, providing insights into the authentication states, vulnerabilities, and potential for misuse within the AD environment.
Rubeus.exe dump /luid: /nowrap
Tip: To dump a specific ticket, use the triage module above and specify the luid when running the dump command.
CreateNetOnly
This module helps create a process that runs under a designated user's context, aiding in lateral movement by allowing an attacker to execute commands or access resources as another user.
Rubeus.exe createnetonly /program:"cmd.exe" /domain: /user: /password:
Tip: To show the newly spawned program (i.e., cmd.exe, powershell.exe, etc), add the /show flag to the command.
Is your team looking to leverage Rubeus to strengthen your AD defenses? Contact us today and explore how we can enhance your security with in-depth penetration testing.