Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
orpheus — Bypassing Kerberoast Detections with Modified KDC Options and Encryption Types | Kitploit
Tools/GitHubGitHub/trustedsec/orpheus
Password AttacksExploitationPenetration TestingAuthenticationRed Teaming
GitHubtrustedsec/orpheus

orpheus

Bypassing Kerberoast Detections with Modified KDC Options and Encryption Types

View Repository
421511 year agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Orpheus

Orpheus

Orpheus is a wrapper for a modified version of Impacket's GetUserSPNs.py and kerberosv5.py which alters the KDC Options (Ticket Options) and the Encryption Type for Kerberoasting.

Side Note: Orpheus is named after the Greek god that was able to get past Cerberus (the three headed dog) to get into Hades.

Installation / Running

You will need to install the latest version of Impacket. This was tested on the 0.10.0 release. Then

root@kitploit:~
git clone https://github.com/trustedsec/orpheus.git
cd orpheus
python3 orpheus.py

Commands

Type help for a listing of commands. To change the KDC options, enter the number of the option and press enter.

root@kitploit:~
Commands:
    0 to 31                       Toggles the specific KDC Option flag.
    hex <value>                   Sets KDC Options from a hexadecimal value.
    cred <value>                  Sets the GetUserSPNs.py credential parameter.
    dcip <value>                  Sets the GetUserSPNs.py domain IP parameter.
    file <value>                  Sets the GetUserSPNs.py filename parameter.
    enc                           Toggles the encryption type from 23 (RC4) to 18 (AES-256).
    sleep                         Set the time to wait before requesting each TGS.
    jitter                        Set the Jitter to avoid waiting a constant sleep time between each TGS request.
    command                       Show the GetUserSPNs.py command with specified options.
    run                           Runs GetUserSPNs.py with the selected options.
    clear                         Clears the screen and displays the options.
    exit                          Exits the script.

Video

Check out the video on YouTube

Blog Post

Check out the blog post on TrustedSec

Download Tool