LogoClawIndex
CasesSkillsAbout
LogoClawIndex

kerberoasting-active-directory - Kerberoasting Active Directory

Extract Service Principal Name ticket hashes from Active Directory and crack them offline to obtain service account passwords.

Tags

Updated: 2026-09-18

Capabilities

Typical Inputs

Typical Outputs

What this skill does

  • Identify Service Principal Names
  • Request TGS ticket hashes
  • Crack TGS hashes offline
  • Verify cracked account credentials

Inputs

  • Valid domain credentials
  • Domain Controller IP address
  • Password wordlist

Outputs

  • Extracted TGS ticket hashes file
  • Plaintext service account passwords
  • Assessment report

Requirements

  • Authorized assessment scope
  • Windows domain environment
  • Installed tools Impacket Hashcat Rubeus

Source

  • Spec: SKILL.md

ClawIndex

OpenClaw Skills & Use Case Index

ClawIndex is an ecosystem-driven index of OpenClaw skills and real-world use cases.

Index

Skills·
Cases

Meta

About·
Disclaimer·
Email·
GitHub
© 2026 ClawIndex All Rights Reserved.
active-directory
kerberos
kerberoasting
impacket
red-teaming
spn
Identify Service Principal Names
Request TGS ticket hashes
Crack TGS hashes offline
Verify cracked account credentials
Valid domain credentials
Domain Controller IP address
Password wordlist
Extracted TGS ticket hashes file
Plaintext service account passwords
Assessment report