CompTIA PenTest+ (PT0-003)Attacks and ExploitsMedium

During an internal engagement, a tester enumerates several Active Directory accounts with Service Principal Names (SPNs) and requests TGS tickets for each. The tickets are exported to a file for offline cracking. Which hashcat mode should be specified to crack these extracted tickets?

  1. A22000
  2. B13100
  3. C1000
  4. D5600
Show answer & explanation

Correct answer: B. 13100

Hashcat mode 13100 is designed for Kerberos 5, etype 23, TGS-REP hashes obtained during a Kerberoasting attack. Mode 1000 targets NTLM hashes, 22000 targets WPA-PBKDF2 handshakes, and 5600 targets NetNTLMv2.

Why the other options are wrong

  • A. 22000 is used for WPA/WPA2 handshake cracking.
  • C. 1000 is for raw NTLM hashes, not Kerberos tickets.
  • D. 5600 targets NetNTLMv2 challenge-response hashes.

Kerberoasting

An attack where a tester requests service tickets (TGS) for accounts with SPNs and cracks them offline to recover service account passwords.

  • Requires only a valid domain user, not admin rights
  • Cracked with hashcat mode 13100
  • Mitigated by strong service account passwords and gMSA

Memory trick: 'Kerber-oast the ticket, then hash 13100 to crack it'

More Attacks and Exploits questions