Rubeus is an open-source C# toolkit for interacting with and abusing Kerberos in Active Directory environments. It is used by penetration testers and threat actors for operations including Kerberoasting, ticket enumeration and extraction, ticket submission, delegation abuse, Pass-the-Ticket, and creation or manipulation of forged Kerberos tickets. Its tgtdeleg capability can obtain a usable ticket-granting ticket for the current user through Kerberos GSS-API delegation abuse without requiring host elevation. With access to high-value Active Directory secrets such as the KRBTGT key, Rubeus can be used to forge or modify tickets to impersonate privileged users and enable domain-wide access. The tool has been observed in post-compromise activity, including use by QBot operators and in Earth Krahang-linked operations. Rubeus targets Windows Active Directory environments and is frequently used for credential access, privilege escalation, and lateral movement.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The reported noPac fallback used CVE-2021-42278 and CVE-2021-42287 to request a ticket-granting ticket through the PaperCut server's domain computer account, impersonate the domain controller, and forge a high-privilege service ticket.
Where LSASS memory dumping failed, agents reportedly fell back to the noPac vulnerabilities, CVE-2021-42278 and CVE-2021-42287, using Rubeus or Certipy to obtain and forge high-privilege Kerberos tickets.
BadSuccessor is a critical attack vector that emerged following the release of Windows Server 2025. Under certain conditions, this server version enables users to leverage delegated Managed Service Accounts (dMSAs) to elevate privileges within Active Directory environments running Windows Server 2025. At the time of writing this article, no patch exists for this issue.
This detection leverages Windows Security Event Logs to identify TGT requests with unusual fields, which may indicate the use of tools like Rubeus following the exploitation of CVE-2021-36942 (PetitPotam).
6 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"Rubeus uses the forged certificate to request a TGT as a Domain Admin."
Wizard Spider has utilized tools such as Empire, Cobalt Strike, Cobalt Strike, Rubeus, AdFind, BloodHound, Metasploit, Advanced IP Scanner, Nirsoft PingInfoView, and SoftPerfect Network Scanner for targeting efforts.
The threat actor also used the Rubeus C# toolset for raw Kerberos interaction and abuse...
“To secure long-term access to the environment, the SVR used the Rubeus toolkit to craft Ticket Granting Tickets (TGTs).”
“To secure long-term access to the environment, the SVR used the Rubeus toolkit to craft Ticket Granting Tickets (TGTs).”
25 distinct techniques documented for this family, organized by ATT&CK tactic.
You can specify if you want to use Kerberos or NTLM authentication. If you choose Kerberos, the tool will create a sacrificial token and use Rubeus to import/ask for the ticket. If NTLM is specified, the tool will use SharpKatz SetThreadToken or LogonUser impersonation.
Shadow Credentials - это атака на механизм хранения учётных данных в Active Directory, которая позволяет добавить в атрибут msDS-KeyCredentialLink объекта (пользователя или компьютера) пару ключей, а затем использовать их для получения билета Kerberos (TGT) от имени этого объекта.
When the state is set to 2 (Completed), the Windows Domain Controller (the KDC) says: “Okay, the migration is completed. This new dMSA is now the official replacement. I will give this dMSA all the powers and group memberships that the old account used to have.”
After approximately 5 minutes, the malicious actors executed the Exec IcedID command to execute code by injecting the code into a cmd.exe instance.
Where memory dumping came up empty, the agent fell back to the noPac vulnerabilities, CVE-2021-42278 and CVE-2021-42287. | “Where memory dumping came up empty, the agent fell back to the noPac vulnerabilities, CVE-2021-42278 and CVE-2021-42287.”
You can specify if you want to use Kerberos or NTLM authentication. If you choose Kerberos, the tool will create a sacrificial token and use Rubeus to import/ask for the ticket. If NTLM is specified, the tool will use SharpKatz SetThreadToken or LogonUser impersonation.
Shadow Credentials - это атака на механизм хранения учётных данных в Active Directory, которая позволяет добавить в атрибут msDS-KeyCredentialLink объекта (пользователя или компьютера) пару ключей, а затем использовать их для получения билета Kerberos (TGT) от имени этого объекта.
After approximately 5 minutes, the malicious actors executed the Exec IcedID command to execute code by injecting the code into a cmd.exe instance.
You can specify if you want to use Kerberos or NTLM authentication. If you choose Kerberos, the tool will create a sacrificial token and use Rubeus to import/ask for the ticket. If NTLM is specified, the tool will use SharpKatz SetThreadToken or LogonUser impersonation.
Access Token Manipulation (ATT&CK technique: T1134) ... this section will explain how attackers can abuse access tokens and target the fundamental trust relationships in Windows domains to compromise entire networks.
The createnetonly action will use the CreateProcessWithLogonW() API to create a new hidden (unless /show is specified) process with a SECURITY_LOGON_TYPE of 9 (NewCredentials), the equivalent of runas /netonly.
When the state is set to 2 (Completed), the Windows Domain Controller (the KDC) says: “Okay, the migration is completed. This new dMSA is now the official replacement. I will give this dMSA all the powers and group memberships that the old account used to have.”
Customers leveraging the Palo Alto Networks AutoFocus tool can track initially identified samples and tools under the Fireye_RedTeam_Tools, Rubeus, AndrewSpecial, KeeFarce, SafetyKatz, InveighZero, GadgetToJScript, SeatBelt, RuralBishop, SharpView, and SharpZeroLogon tags.
Workstations store Kerberos tickets in the Local Security Authority Subsystem Service (LSASS) memory after user authentication. Attackers with administrative privileges on compromised systems can extract these tickets using tools like Mimikatz or Rubeus.
When the state is set to 2 (Completed), the Windows Domain Controller (the KDC) says: “Okay, the migration is completed. This new dMSA is now the official replacement. I will give this dMSA all the powers and group memberships that the old account used to have.”
мы можем добавить свой ключ и залогиниться... есть протокол (PKINIT), который позволяет логиниться без пароля. Есть хранилище ключей (msDS-KeyCredentialLink). Есть права, которые позволяют в это хранилище писать.
The team used a password hash to request a Kerberos TGT and then a Kerberos service ticket; it also used Rubeus asktgs to request service tickets used for Seamless SSO.
Both the Sapphire and Diamond Ticket attacks decrypt a legitimate TGT and change its PAC, and in order to do that, the adversary needs to have access to the KRBTGT account’s key (the password hash). | Diamond and Sapphire Tickets are forged TGTs created by modifying a legitimate TGT, which gives it additional privileges or a new identity.
“[The agent] exploited the S4U2self flaw to impersonate the domain controller, and forged a high-privilege service ticket.”
One additional account, which was the only one with preauthentication disabled, was compromised via AS-REP roasting.
13 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
44 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Kerberos-focused post-exploitation tool used to request a Domain Admin ticket-granting ticket using an abused certificate.
Used to forge and inject a Golden Ticket for Kerberos authentication, enabling privilege escalation to domain-level administrative access.
Rubeus is referenced as an executable offensive security/post-exploitation tool present on the tester's Kali VM and detected by Windows Defender during AppLocker testing.
Post-exploitation tool used to forge Kerberos Diamond Tickets for authentication abuse.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.