rubeus
Warn
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONCREDENTIALS_UNSAFEPRIVILEGE_ESCALATION
Full Analysis
- [COMMAND_EXECUTION]: Provides detailed command-line examples for running
Rubeus.exe, targeting sensitive Kerberos authentication protocols. - [CREDENTIALS_UNSAFE]: Documents methods for harvesting and dumping TGT/TGS tickets, including specific instructions for dumping tickets from LSASS memory, which exposes sensitive authentication material.
- [PRIVILEGE_ESCALATION]: Includes instructions for advanced Kerberos abuse techniques such as delegation misuse, pass-the-ticket (PTT), and forging Golden, Silver, and Diamond tickets to achieve administrative access and facilitate lateral movement.
Audit Metadata