Possible AS-REP Roasting Attack
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
1 Hour
Deduplication Period
1 Day
Required Data
Requires all of the following: XDR Agent XDR Agent with eXtended Threat Hunting (XTH)
Detection Modules
Identity Analytics
ATT&CK Tactic
Credential Access (TA0006)
ATT&CK Technique
Steal or Forge Kerberos Tickets: AS-REP Roasting (T1558.004)
Severity
Medium
Description
A user enumerated all accounts that don't require pre-authentication in the organization and specifically requested tickets for those accounts. This is typically a sign of an AS-REP Roasting attack.
Attacker's Goals
Crack account credentials by obtaining an easy-to-crack Kerberos ticket.
Investigative actions
Check who used the host at the time of the alert, to rule out a benign service or tool requesting weak Kerberos encryption.
Variations
Was this helpful?
