How ASRepCatcher uses ARP poisoning to obtain crackable AS-REP hashes from any authenticating user, even when Kerberos preauthentication is enabled.
Resources
Blog
Hunter Wade
Blogs by Hunter Wade
Step-by-step walkthrough of cracking NTLMv1-SSP hashes with rainbow tables, including how to coerce auth, disable ESS, recover NT hashes, and remediate.