> For the complete documentation index, see [llms.txt](https://notes.programmersecurity.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://notes.programmersecurity.com/network-penetration-testing/88-pentesting-kerberos.md).

# 88 - Pentesting Kerberos

## Kerbrute

To enumerate and Find Valid Usernames we can use Kerbrute

{% code overflow="wrap" %}

````python
```
## kerbrute enumusers command

kerbrute userenum -d <domain-name> --dc <domain-name> <wordlist-path>       # make sure you use different wordlists
kerbrute userenum -d <domain-name> -dc-ip <IP-Address> <wordlist-path>

EXAPMLE:

kerbrute userenum -d scrm.local --dc scrm.local /usr/share/wordlists/kerberos_enum_userlists/A-ZSurnames.txt

kerbrute userenum -d baby.vl --dc baby.vl users.txt
````

{% endcode %}
