CompTIA PenTest+ (PT0-003)Attacks and ExploitsMedium
During an internal engagement, a tester enumerates several Active Directory accounts with Service Principal Names (SPNs) and requests TGS tickets for each. The tickets are exported to a file for offline cracking. Which hashcat mode should be specified to crack these extracted tickets?
- A22000
- B13100
- C1000
- D5600
Show answer & explanationAnswer & explanation
Correct answer: B. 13100
Hashcat mode 13100 is designed for Kerberos 5, etype 23, TGS-REP hashes obtained during a Kerberoasting attack. Mode 1000 targets NTLM hashes, 22000 targets WPA-PBKDF2 handshakes, and 5600 targets NetNTLMv2.
Why the other options are wrong
- A. 22000 is used for WPA/WPA2 handshake cracking.
- C. 1000 is for raw NTLM hashes, not Kerberos tickets.
- D. 5600 targets NetNTLMv2 challenge-response hashes.
Kerberoasting
An attack where a tester requests service tickets (TGS) for accounts with SPNs and cracks them offline to recover service account passwords.
- Requires only a valid domain user, not admin rights
- Cracked with hashcat mode 13100
- Mitigated by strong service account passwords and gMSA
Memory trick: 'Kerber-oast the ticket, then hash 13100 to crack it'