Skip to content
OPS // KITitspentest.sh

E-ROA

ROADtools Hybrid

dirkjanm's companion utilities to ROADtools for hybrid Azure AD Connect environments — on-prem AD synced with Entra ID.

Official siteBack to catalog

OVERVIEW

ROADtools Hybrid (github.com/dirkjanm/roadtools_hybrid) is not a separate framework but a small set of companion utilities dirkjanm publishes alongside the main ROADtools project specifically for hybrid identity — tenants where on-prem Active Directory is synced into Entra ID via Azure AD Connect. It uses the Azure AD Connect synchronization API, which supports more account properties than the regular Microsoft Graph or legacy AAD Graph even under the same privilege level.

Its two headline capabilities are registering a certificate on a hybrid-joined computer account (`setcert.py`, given a previously created or taken-over computer account, so `roadtx` can then register the device in Entra ID) and extracting Kerberos material from a `roadtx`-obtained PRT — a partial on-prem TGT usable with tools like Impacket, or an Entra Kerberos TGT usable for Kerberos auth against Azure file shares.

USE CASES

Practical use cases

  • 01

    Registering a certificate on a compromised or created computer account to hybrid-join a device in Entra ID.

  • 02

    Extracting a partial on-prem Kerberos TGT from a roadtx PRT for use with Impacket against on-prem AD.

  • 03

    Extracting an Entra Kerberos TGT from a PRT to authenticate to Azure file shares via Kerberos.

  • 04

    Abusing a Global Admin or Sync-account token via the Azure AD Connect sync API to modify hybrid account properties.

QUICK START

During Entra ID assessments of hybrid (Azure AD Connect-synced) tenants, once a computer account or sync-account token is available.

  1. Clone the repository and install dependencies with `pip install -r requirements.txt` (plus `pycryptodome` on Python 3.10+).
  2. Obtain or take over a hybrid-joined computer account's credentials, e.g. with Impacket's `addcomputer.py`.
  3. Run `setcert.py` against a domain controller with that computer account to register a certificate for the hybrid join.
  4. After the sync delay, use `roadtx` with the generated certificate to complete device registration in Entra ID.
python — bash
python setcert.py 10.0.1.1 -t 'DESKTOP-NAME$' -u 'domain\DESKTOP-NAME$' -p computerpasswordhere

BEFORE YOU RUN IT

What to check before running it

This is not a separate, independently named tool — it is dirkjanm's hybrid-identity companion repo to ROADtools; treat it as an extension of that project rather than a standalone framework when scoping work.

Certificate sync between on-prem AD and Entra ID can take up to 30 minutes, and the Azure AD Connect sync-account token this relies on is a high-value credential — confirm with the client how its use will appear in their sync and Entra ID sign-in logs.

Modifying computer-account or hybrid-join properties is an active, potentially disruptive action against production identity infrastructure — get explicit written authorization before running `setcert.py` or sync-API writes outside a lab.

KEEP EXPLORING

View the whole phase →