permalink: spells/kerbrute
tags:
- Protocol/Kerberos
- Protocol/UDP
- OS/Windows/ActiveDirectory
- Application/Kerbrute
- AttackCycle/Reconnaissance/BruteForcingKerbrute user enumeration works by sending a single UDP packet to the authentication service to begin the authentication process, but then doesn't complete the transaction as to avoid an actual login failure (and the associated logging). While this doesn't grant access to anything, it does allow domain users to be enumerated using a wordlist.
To use Kerbrute you need to meet one of the following requirements:
--dc flag.