Silver Ticket
SILVER TICKET
A Silver Ticket can be obtained for services that use Kerberos as an authentication mechanism and are used to generate tickets to access that particular resource and the system that hosts the resource (e.g., SharePoint).
Forging a Service Ticket (ST) require machine account password (key) or NT hash of the service account.
1) Create a ticket for the service
2) Use same steps as a golden ticket
Inject the ticket
Obtain a shell
Silver Ticket on Linux
Services to target with a Silver Ticket
Service Type --> Service Silver Tickets --> Attack
Silver Ticket Example
Requirements: Machine account NTLM hash
1) Mimikatz
2) Rubeus
Forge silver ticket
3) Empire C2
Post Exploitation Techniques Examples
Map drive
Copy malware to Domain Administrator startup folder on DC
CMD
Netcat
Other ticket combinations
Technique
Required Service Ticket
Last updated