Orpheus
Bypassing Kerberoast Detections with Modified KDC Options and Encryption Types
Install / Use
/learn @trustedsec/OrpheusREADME
Orpheus

Orpheus is a wrapper for a modified version of Impacket's GetUserSPNs.py and kerberosv5.py which alters the KDC Options (Ticket Options) and the Encryption Type for Kerberoasting.
Side Note: Orpheus is named after the Greek god that was able to get past Cerberus (the three headed dog) to get into Hades.
Installation / Running
You will need to install the latest version of Impacket. This was tested on the 0.10.0 release. Then
git clone https://github.com/trustedsec/orpheus.git
cd orpheus
python3 orpheus.py
Commands
Type help for a listing of commands. To change the KDC options, enter the number of the option and press enter.
Commands:
0 to 31 Toggles the specific KDC Option flag.
hex <value> Sets KDC Options from a hexadecimal value.
cred <value> Sets the GetUserSPNs.py credential parameter.
dcip <value> Sets the GetUserSPNs.py domain IP parameter.
file <value> Sets the GetUserSPNs.py filename parameter.
enc Toggles the encryption type from 23 (RC4) to 18 (AES-256).
sleep Set the time to wait before requesting each TGS.
jitter Set the Jitter to avoid waiting a constant sleep time between each TGS request.
command Show the GetUserSPNs.py command with specified options.
run Runs GetUserSPNs.py with the selected options.
clear Clears the screen and displays the options.
exit Exits the script.
Video
Check out the video on YouTube
Blog Post
Check out the blog post on TrustedSec
Related Skills
node-connect
340.5kDiagnose OpenClaw node connection and pairing failures for Android, iOS, and macOS companion apps
frontend-design
84.2kCreate distinctive, production-grade frontend interfaces with high design quality. Use this skill when the user asks to build web components, pages, or applications. Generates creative, polished code that avoids generic AI aesthetics.
openai-whisper-api
340.5kTranscribe audio via OpenAI Audio Transcriptions API (Whisper).
commit-push-pr
84.2kCommit, push, and open a PR
