Case D86CD3 · Identity & AD · L2 Practitioner
AS-REP Roasting
Practise as: Explain it
- 01 What is it?
- 02 How is it abused?
- 03 How do you stop it?
What a strong answer covers
Try it out loud first. Then check yourself:
- Targets accounts with "Do not require Kerberos preauthentication" set (UF_DONT_REQUIRE_PREAUTH)
- Attacker sends an AS-REQ without pre-auth; the AS-REP contains data encrypted with the user key, crackable offline
- No credentials needed if usernames are known; tools: Rubeus asreproast, Impacket GetNPUsers.py
- Detect: 4768 with Pre-Authentication Type 0 and RC4; find exposed accounts via LDAP userAccountControl filter
- Fix: re-enable pre-auth on every account and enforce strong passwords on any legacy exception
Go deeper
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.