Task 4 - Enumerating Users via Kerberos

Task 4 Enumeration Enumerating Users via Kerberos

In order to use Kerbrutearrow-up-right to enumerate the users, you will also need to download the provided User Listarrow-up-right and Password Listarrow-up-right which you can get from Sq00kyarrow-up-right's repo attacktive-directory-toolsarrow-up-right.

What command within Kerbrutearrow-up-right will allow us to enumerate valid usernames?

circle-exclamation

Kerbrutearrow-up-right bruteforces and enumerates valid Active Directory accounts through Kerberos Pre-Authentication. The following commandarrow-up-right will attempt to enumerate valid usernames given a list of usernames to try:

kerbrute
kerbrute userenum -d domain.tld usernames.txt
chevron-rightReveal Flag 🚩hashtag

🚩userenum

What notable account is discovered?

(These should jump out at you)

chevron-rightReveal Flag 🚩hashtag

🚩svc-admin

What is the other notable account is discovered?

(These should jump out at you)

chevron-rightReveal Flag 🚩hashtag

🚩backup

Last updated