AS-REP roasting
TL;DR
AS-REP roasting targets accounts configured with “do not require Kerberos pre-authentication”. For those, part of the login response is encrypted with the user’s password hash and can be cracked offline — without even needing valid credentials first. The fix is to require pre-auth and use strong passwords.
What it is
Kerberos pre-authentication is what stops an attacker from asking “prove this user’s password to me” without knowing it. A small number of accounts have it switched off, usually for legacy compatibility, and those are the target.
How it works
For a pre-auth-disabled account, an attacker can request an authentication response whose contents are encrypted with the account’s password hash, then crack it offline. Unlike Kerberoasting, this doesn’t need any prior foothold — just knowledge of a vulnerable username.
How to detect it
- Alert on authentication requests for accounts without pre-auth, and audit which accounts have that flag set.
How to defend
- Require Kerberos pre-authentication on every account that possibly can.
- Strong passwords, so anything that does get roasted doesn’t crack.
Reference: MITRE ATT&CK T1558.004.