# Rubeus: a C# toolkit for raw Kerberos ticket abuse

> Rubeus is a command-line C# toolset for requesting, forging, extracting and applying Kerberos tickets on Windows. It is built for red teamers and Active Directory security testers, and it is not a general-purpose authentication library.

**GhostPack/Rubeus** — Trying to tame the three-headed dog.

- Repository: https://github.com/GhostPack/Rubeus
- Stars: 5,181 · Forks: 901
- Language: C#
- License: NOASSERTION
- Published: 2026-09-23 · Updated: 2026-09-23 · Language: en
- Canonical page: https://hysenlabs.com/projects/ghostpack-rubeus

## What Rubeus does that built-in Windows tools do not

Windows ships Kerberos support inside lsass, and the visible surface is small: klist lists tickets, and that is roughly where the command line stops. You cannot ask Windows to build a TGT from an AES256 hash, write it to a file, and apply it to a chosen logon session. Rubeus exposes those operations as subcommands. The README describes it as a C# toolset for raw Kerberos interaction and abuses, and the command list backs that up: asktgt, asktgs, renew, s4u, golden, silver, diamond, ptt, purge, describe, triage, klist, dump, tgtdeleg, monitor, harvest, kerberoast, asreproast, createnetonly, changepw, hash, tgssub and kirbi. The audience is narrow. These are post-exploitation operations against Active Directory, written for red teamers and penetration testers who already understand ticket flags, encryption types and delegation. An application developer looking for a way to authenticate users against a KDC is in the wrong repository.

## How the ticket pipeline is wired

Each subcommand maps to a step in the Kerberos exchange. asktgt sends an AS-REQ to a domain controller and returns a TGT, either printed as base64, written with /outfile, or applied to a logon session with /ptt. asktgs takes that TGT and requests a service ticket. The /luid and /createnetonly options control where the resulting ticket lands, which matters because a ticket is only useful to the process whose logon session holds it. The README gives this shape for a hash-based request: Rubeus.exe asktgt /user:USER /rc4:HASH /ptt. Encryption type is explicit throughout, with /enctype accepting DES, RC4, AES128 or AES256, and separate flags for /des, /rc4, /aes128 and /aes256. Ticket material can also be converted: asrep2kirbi turns AS-REP output into a .kirbi file, and kirbi handles the format directly. Forging commands (golden, silver, diamond) sit at the other end, constructing tickets rather than requesting them. The README credits the ASN.1 encoding to Thomas Pornin's DDer library and the PAC encoding to NtApiDotNet, which tells you the parsing layer is borrowed rather than hand-rolled.

## Building Rubeus from Rubeus.sln

The repository is a Visual Studio solution: Rubeus.sln at the top level, with the source in the Rubeus/ directory. The README's Compile Instructions section covers building it, and a subsection on targeting other .NET versions, which matters because the runtime available on a target host constrains which build you can run. The README also notes that Rubeus can be built as a library and run through PowerShell, including over PSRemoting. There is no package manager install path documented in the README, so the workflow is clone, open the solution, build. A minimal build from a developer command prompt looks like this:

```bash
git clone https://github.com/GhostPack/Rubeus.git
cd Rubeus
msbuild Rubeus.sln /p:Configuration=Release
```

The README uses Rubeus.exe as the invocation form throughout, so the expected output is a Rubeus.exe in the build output directory. A first real use is a TGT request that also applies the ticket to the current session:

```bash
Rubeus.exe asktgt /user:USER /rc4:HASH /ptt
```

The /ptt flag means pass-the-ticket: instead of writing a file, the ticket is injected into the current logon session. If you would rather inspect it first, drop /ptt and add /outfile:ticket.kirbi. The README's own examples use this pattern, and it is the fastest way to confirm the build works before trying anything more involved.

## The opsec section is the honest part of the README

Most offensive tooling documentation skips the question of what the tool looks like from the defender's side. Rubeus does not. The README carries an Opsec Notes section with an overview, a weaponization subsection, and worked examples for credential extraction and over-pass-the-hash. That is unusual and worth reading before you run anything, because the tool's own authors are telling you which operations are noisy. The kerberoast section has its own opsec subsection for the same reason. Treat this as a design constraint rather than a footnote: a tool that makes raw Kerberos requests from userland produces traffic and event log entries that differ from normal Windows authentication, and the README is explicit that some subcommands are more conspicuous than others. If your engagement does not include a detection-engineering component, the opsec notes still tell you which commands to avoid on a sensitive network.

## Where Rubeus is the wrong choice

Rubeus is Windows-only in practice. It is a C# binary built against .NET, and every example in the README uses Rubeus.exe with Windows paths such as C:\Windows\System32\cmd.exe and C:\temp\leaked.pfx. There is no documented Linux or macOS workflow. Second, it is offensive tooling with a narrow scope: it does Kerberos, and it does not do LDAP enumeration, SMB relay, or credential dumping from memory. If your task is to enumerate directory objects or move laterally over SMB, Rubeus will not help and you will be pairing it with something else. Third, the release history is thin. The most recent release listed is 1.6.4 (Rubeus-3.5) from 2021-08-03, while the last push to master was on 2026-05-21. That gap means the tagged release is old and the interesting changes live on master, so a build from the default branch is the realistic option, and you should read CHANGELOG.md rather than trusting the release tag. Finally, the version banner in the README's usage output reads v2.3.3, which does not match the 1.6.4 release tag or the Rubeus-3.5 label. Versioning here is confusing, and you should not assume a release number tells you what is in the binary.

## Rubeus versus building on Kerberos.NET

The closest alternative in the same space is Kerberos.NET, the library by Steve Syfuhs from which Rubeus adapted its PKINIT code (RFC4556). The difference is the layer each one occupies. Kerberos.NET is a library you reference from your own application; you write the code that requests tickets, and you decide what to do with them. Rubeus is a finished executable with subcommands, so you get the ticket operations without writing the ASN.1 or the KDC exchange, but you also get its command-line surface and its assumptions about logon sessions. If you are building a product that authenticates users, Kerberos.NET is the right shape. If you are on an engagement and need a TGT from a hash in the next five minutes, Rubeus is. The README is candid about the lineage: it credits Kekeo (CC BY-NC-SA 4.0) and MakeMeEnterpriseAdmin (GPL v3.0) as the source of the hard weaponization work, and DDer for ASN.1.

## Licence and upgrade cost

Rubeus is licensed under BSD 3-Clause, and the LICENSE file is at the top level. That is only part of the picture. The README states that Rubeus is heavily adapted from Kekeo, which is CC BY-NC-SA 4.0, and from MakeMeEnterpriseAdmin, which is GPL v3.0. Those upstream licences carry conditions that BSD 3-Clause does not, including non-commercial and share-alike terms, and the README does not resolve how they interact with the BSD 3-Clause grant on the combined work. That is a question for your own legal review, not something to settle by reading the repository. On upgrades: there is no package manager, so an upgrade means pulling master and rebuilding from Rubeus.sln. The README documents targeting other .NET versions, so a rebuild may need a different target framework depending on the host. Nothing in the README describes a migration path or a rollback procedure, so pin the commit you build from and keep the binary you tested.

## Conclusion

Rubeus suits red teamers and AD security testers who already read Kerberos ticket internals and need scriptable ticket operations from a Windows command line. It is the wrong tool for application developers who want to authenticate users, and for anyone who cannot build a .NET project from source or run it in an authorized lab. Before adopting it, check the BSD 3-Clause LICENSE file against the Kekeo and MakeMeEnterpriseAdmin lineage described in the README, and confirm the build output from Rubeus.sln matches the .NET version your target hosts carry.

## FAQ

### What is the Rubeus tool?

Rubeus is a C# toolset for raw Kerberos interaction and abuses, heavily adapted from Kekeo and MakeMeEnterpriseAdmin. It runs as a Windows command-line executable with subcommands such as asktgt, kerberoast and ptt.

### How do you build Rubeus from source?

The repository contains Rubeus.sln at the top level with the source in the Rubeus/ directory, and the README has Compile Instructions plus a subsection on targeting other .NET versions. There is no package manager install documented, so building the solution is the path.

### Which Kerberos operations does Rubeus support?

The README lists ticket requests and renewals (asktgt, asktgs, renew, brute/spray), constrained delegation abuse (s4u), ticket forgery (golden, silver, diamond), ticket management (ptt, purge, describe), extraction and harvesting (triage, klist, dump, tgtdeleg, monitor, harvest), roasting (kerberoast, asreproast) and miscellaneous commands such as changepw and tgssub.

### What licence does Rubeus use?

Rubeus is licensed under BSD 3-Clause, but the README states it is heavily adapted from Kekeo (CC BY-NC-SA 4.0) and MakeMeEnterpriseAdmin (GPL v3.0), so the upstream terms also apply to parts of the codebase.

### Does Rubeus run on Linux or macOS?

No Linux or macOS workflow is documented. Every example in the README uses Rubeus.exe with Windows paths such as C:\Windows\System32\cmd.exe, and the project is a C# solution built on Windows tooling.

## Sources

- [GhostPack/Rubeus on GitHub](https://github.com/GhostPack/Rubeus)
- [Issues](https://github.com/GhostPack/Rubeus/issues)
- [README](https://github.com/GhostPack/Rubeus/blob/master/README.md)
- [Releases](https://github.com/GhostPack/Rubeus/releases)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/ghostpack-rubeus
