NetExec SMB Timeroasting

HashUsernameLinuxWindowsCredential AccessTimeroasting

NetExec (formerly CrackMapExec) performs a Timeroasting attack via the SMB service. This command targets the remote Windows host and abuses the Kerberos protocol by manipulating ticket lifetimes or requesting renewable service tickets. It can help attackers obtain long-lived Kerberos tickets for offline cracking or later lateral movement.

Command Reference:

Target IP: 10.10.10.1
Module: timeroast

Command

nxc smb 10.10.10.1 -M timeroast

References