AS-REP roasting is one of those identity attacks that can sit quietly in the background until an attacker has already gained useful foothold. For defenders, the challenge is not understanding the offensive technique in detail, but knowing what telemetry exists, what patterns matter, and how to turn that into a reliable detection. In a UK…
First seen on securityboulevard.com
Jump to article: securityboulevard.com/2026/08/detecting-as-rep-roasting-in-active-directory-authentication-logs/
![]()

