
Lightweight Python checker that tests Active Directory credentials for exposure to CVE-2022-33679 (Kerberos AS-REP roast without pre-authentication). Detects vulnerability without exploitation.
Lightweight checker that tests whether a set of Active Directory credentials is exposed to CVE-2022-33679 (Kerberos AS-REP roast without pre-authentication). The code is derived from Bdenneu/CVE-2022-33679 and keeps only the detection path—it never attempts exploitation. It isn't an exploit!.
uv for environment management, or standard python3 -m venvrequirements.txt: impacket==0.10.0, arc4==0.3.0uv venv
source .venv/bin/activate
uv pip install -r requirements.txt
python3 -m venv .venv
source .venv/bin/activate
pip install -r requirements.txt
uv run python CVE-2022-33679_Checker.py DOMAIN/username [-dc-ip DC_IP] [-ts] [-debug]
| Argument | Description |
|---|---|
DOMAIN/username | Credential to test, in domain/user format. The domain part is required. |
-dc-ip | (Optional) IP of the Domain Controller. When omitted, the script resolves the FQDN from DOMAIN. |
-ts | Prefixes logs with timestamps. |
-debug | Enables verbose logging, including Impacket installation path. |
Usuario no encontrado en el dominio.1; a safe response exits with 0.Check a user against an explicit DC IP:
uv run python CVE-2022-33679_Checker.py CONTOSO/alice -dc-ip 192.168.1.10
Possible outcomes:
Sistema vulnerable a CVE-2022-33679: Se recibió AS-REP sin pre-autenticaciónSistema NO vulnerable: Requiere pre-autenticación KerberosDomain should be specified!: make sure the target is DOMAIN/user, not just user.Error de Kerberos: ...: enable -debug for more context, verify the DC IP, and confirm the account name.Operate the checker only on systems you are authorized to test. The script is intended for defensive validation of CVE-2022-33679 mitigations.