Skip to content
REDMAW

Internal Infrastructure

AS-REP Roasting

Certain Active Directory account configurations let an attacker obtain authentication material that can be attacked offline without knowing the password.

RedMaw

Definition

Where an Active Directory account does not require Kerberos pre-authentication, an attacker can request authentication material for that account and attack it offline, without needing the account's password to begin.

Why the configuration exists

Pre-authentication is sometimes disabled to accommodate an application or appliance that cannot perform it. The setting is then rarely revisited, and it is not visible in the places people look for privileged-access problems.

Why offline matters

An offline attack is unconstrained by lockout policy, rate limiting or authentication monitoring. It proceeds at the attacker's pace, with no further interaction with the environment, so weak passwords on such accounts are considerably more exposed than the policy suggests.

Where it leads
  1. Internal Foothold
  2. Directory Account
  3. Offline Credential Attack
  4. Identity
  5. Privileged Resource

Each hop validated by successful exploitation

Tags

  • active directory
  • kerberos
  • credentials

Validation

How RedMaw validates this attack

Validation runs only inside authorized scope, with agreed exploitation limits.

  1. 01Enumerate accounts not requiring Kerberos pre-authentication
  2. 02Establish which of those accounts hold meaningful privilege
  3. 03Assess offline attack exposure for those accounts
  4. 04Report the configuration and the privilege it protects

Stop assuming you are secure. Prove it.

Continuously test what an attacker can actually reach across your applications, SaaS identities, internal infrastructure and AI systems.