AS-REP roasting

intermediateInternal & Active Directory

TL;DR

AS-REP roasting targets accounts configured with “do not require Kerberos pre-authentication”. For those, part of the login response is encrypted with the user’s password hash and can be cracked offline — without even needing valid credentials first. The fix is to require pre-auth and use strong passwords.

What it is

Kerberos pre-authentication is what stops an attacker from asking “prove this user’s password to me” without knowing it. A small number of accounts have it switched off, usually for legacy compatibility, and those are the target.

How it works

For a pre-auth-disabled account, an attacker can request an authentication response whose contents are encrypted with the account’s password hash, then crack it offline. Unlike Kerberoasting, this doesn’t need any prior foothold — just knowledge of a vulnerable username.

How to detect it

How to defend

Reference: MITRE ATT&CK T1558.004.

← Back to Internal & Active Directory