VulnScanners Logo

Active Directory

Kerbrute

Kerberos username enumeration and password spraying.

adkerberos
kerbrute — terminal
$ kerbrute userenum -d domain.local users.txt

What it does

Kerbrute quickly enumerates valid AD usernames and performs low-noise password spraying via Kerberos pre-authentication. It's a common way to find a first valid credential.

Source

https://github.com/ropnop/kerbrute

More Active Directory tools

Need hosted scanning instead of local tooling?

Run a scan in the browser →