A kerberoastable service account doesn't wait for you to finish a 50-million-line wordlist. It waits for your engagement window to close.
ad-audit-wordlist is a shell-script recipe that rebuilds the ~94-million-line Active Directory audit wordlist I use on engagements, for Kerberoasting and hashcat password cracking. It priority-merges two frequency-ordered lists and dedups them in a way that keeps that order, so the likely hits land in the first few million lines where a time-capped crack can still reach them.
This is not a 1 GB download. It is the recipe, so anyone can rebuild the same list from the same two sources, in the same order.
| Source | Size | Access | Role |
|---|---|---|---|
| hashmob "large" research list | ~61.3M lines, frequency-ordered | hashmob.net account | Primary, goes first |
| kerberoast_pws (The-Viper-One) | ~35.6M lines, ~32.7M unique on top of the first list | Public gist | Secondary, service-account passwords |
Merged and deduped with rling (order-preserving, keeps the first occurrence). Result: ~94,000,000 lines.
Cracking against a fixed time budget is a search-order problem, not a coverage problem. Real passwords cluster around a small set of patterns (Summer2024!, company names, keyboard walks), and hashmob's frequency-ranked corpus encodes that clustering from millions of real cracks. Keep the order and hashcat finds the easy 20-30% of accounts in the first pass. Run sort -u on the merge and you get an alphabetized list where a weak password at line 40M costs the same GPU-hours as one at line 4M. rling dedups byte-exact and keeps first-seen order, so the merged list still tries the likely hits first.
The hashmob list sits behind a hashmob.net account under their terms, so re-hosting it is not mine to give. The script pulls the public piece (kerberoast_pws) for you and merges it with your own hashmob download. Everything else (merge order, dedup, output) is scripted and reproducible.
Requirements: bash, curl, xz, awk, and rling on your PATH.
- Get a hashmob.net account, download
hashmob.net.large.foundfrom Research, and drop it next to the script. - Run:
./build-ad-audit-wordlist.shIt downloads kerberoast_pws, normalizes line endings, merges hashmob first, and dedups with rling into combined_audit_base.txt (~94M lines).
Pair the wordlist with OneRuleToRuleThemStill for rule-based mutation against a Kerberoasting hash:
hashcat -m 13100 kerberoast.hash combined_audit_base.txt -r OneRuleToRuleThemStill.ruleMode 13100 is Kerberos 5, etype 23, TGS-REP: the standard hashcat mode for Kerberoasting.
hashmob community, The-Viper-One (kerberoast_pws), Cynosureprime (rling), Stealthsploit (OneRuleToRuleThemStill).
MIT. See LICENSE.
Built by ADScanPro, Active Directory security testing (adscanpro.com).