
Bypassare i rilevamenti Kerberoast con opzioni KDC e tipi di crittografia modificati

Orpheus è un wrapper per una versione modificata di GetUserSPNs.py e kerberosv5.py di Impacket, che modifica le Opzioni KDC (Ticket Options) e il Tipo di Crittografia per il Kerberoasting.
Nota a margine: Orpheus prende il nome dal dio greco che riuscì a superare Cerbero (il cane a tre teste) per entrare nell'Ade.
Dovrai installare l'ultima versione di Impacket. È stata testata sulla release 0.10.0. Poi
git clone https://github.com/trustedsec/orpheus.git
cd orpheus
python3 orpheus.py
Digita help per un elenco dei comandi. Per modificare le opzioni KDC, inserisci il numero dell'opzione e premi invio.
Commands:
0 to 31 Toggles the specific KDC Option flag.
hex <value> Sets KDC Options from a hexadecimal value.
cred <value> Sets the GetUserSPNs.py credential parameter.
dcip <value> Sets the GetUserSPNs.py domain IP parameter.
file <value> Sets the GetUserSPNs.py filename parameter.
enc Toggles the encryption type from 23 (RC4) to 18 (AES-256).
sleep Set the time to wait before requesting each TGS.
jitter Set the Jitter to avoid waiting a constant sleep time between each TGS request.
command Show the GetUserSPNs.py command with specified options.
run Runs GetUserSPNs.py with the selected options.
clear Clears the screen and displays the options.
exit Exits the script.
Guarda il video su YouTube
Leggi l'articolo del blog su TrustedSec