AS-REP Roasting

T1558.004

Sub-technique of T1558 Steal or Forge Kerberos Tickets.View on attack.mitre.org

About this technique

Adversaries may reveal credentials of accounts that have disabled Kerberos preauthentication by Password Cracking Kerberos messages.

Preauthentication offers protection against offline Password Cracking. When enabled, a user requesting access to a resource initiates communication with the Domain Controller (DC) by sending an Authentication Server Request (AS-REQ) message with a timestamp that is encrypted with the hash of their password. If and only if the DC is able to successfully decrypt the timestamp with the hash of the user’s password, it will then send an Authentication Server Response (AS-REP) message that contains the Ticket Granting Ticket (TGT) to the user. Part of the AS-REP message is signed with the user’s password.

For each account found without preauthentication, an adversary may send an AS-REQ message without the encrypted timestamp and receive an AS-REP message with TGT data which may be encrypted with an insecure algorithm such as RC4. The recovered encrypted data may be vulnerable to offline Password Cracking attacks similarly to Kerberoasting and expose plaintext credentials.

An account registered to a domain, with or without special privileges, can be abused to list all domain accounts that have preauthentication disabled by utilizing Windows tools like PowerShell with an LDAP filter. Alternatively, the adversary may send an AS-REQ message for each user. If the DC responds without errors, the account does not require preauthentication and the AS-REP message will already contain the encrypted data.

Cracked hashes may enable Persistence, Privilege Escalation, and Lateral Movement via access to Valid Accounts.

Detection rules6

Rules on DetectionCode tagged with T1558.004.

Sigma0

No Sigma rules are mapped to this technique yet.

Splunk6

RuleTypeRiskData source
Disabled Kerberos Pre-Authentication Discovery With Get-ADUserTTPNULLPowershell Script Block Logging 4104
Disabled Kerberos Pre-Authentication Discovery With PowerViewTTPNULLPowershell Script Block Logging 4104
Kerberos Pre-Authentication Flag Disabled in UserAccountControlTTPNULLWindows Event Log Security 4738
Kerberos Pre-Authentication Flag Disabled with PowerShellTTPNULLPowershell Script Block Logging 4104
Rubeus Command Line ParametersTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows Process With NetExec Command Line ParametersTTPNULLWindows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples1

Software1

Used byProcedure example
ToolRubeus

Rubeus can reveal the credentials of accounts that have Kerberos pre-authentication disabled through AS-REP roasting.

References4

  1. Harmj0y Roasting AS-REPs Jan 2017 Open source
    HarmJ0y. (2017, January 17). Roasting AS-REPs. Retrieved September 23, 2024.
  2. Microsoft Kerberos Preauth 2014 Open source
    Sanyal, M.. (2014, March 18). Kerberos Pre-Authentication: Why It Should Not Be Disabled. Retrieved August 25, 2020.
  3. SANS Attacking Kerberos Nov 2014 Open source
    Medin, T. (2014, November). Attacking Kerberos - Kicking the Guard Dog of Hades. Retrieved March 22, 2018.
  4. Stealthbits Cracking AS-REP Roasting Jun 2019 Open source
    Jeff Warren. (2019, June 27). Cracking Active Directory Passwords with AS-REP Roasting. Retrieved August 24, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.