š¢AS-REPS Roasting
Enumerating accounts with Kerberos pre-auth disabled
Enumerate permissions for group
Set pre-auth not required
Request encrypted AS-REP
Enumerate all users with Kerberos pre-auth disabled and request a hash
Crack the hash with hashcat
Active Directory Kerberos Enumeration and Modification
Enumerating Accounts with Disabled Kerberos Pre-Authentication
First, load the PowerView PowerShell module:
Then, retrieve all users with pre-authentication not required, using:
Or, list only their usernames:
Enumerating Permissions for a Group
To find permissions for a specific group:
For a detailed list:
Disabling Kerberos Pre-Authentication for a User
Load the PowerView script and run:
Requesting Encrypted AS-REP for a User
After loading the ASREPRoast script:
Roasting Users with Pre-Auth Disabled
To enumerate and roast all users:
Cracking the Hash
Finally, crack the retrieved hash using hashcat:
Last updated