AS-REP Roasting
ASREPRoast

If a user's UserAccountControl settings have "Do not require Kerberos pre-authentication" enabled, i.e., Kerberos auth disabled, it is possible to grab the user's crackable AS-REP and brute-force it offline.
Linux

Crack using hashcat Or john
Windows
Enumeration
Powershell script to know users have weak config (Don't req preAuth)
Impacket
Resources
Last updated