shadow-credentials.md (4919B)
1 --- 2 title: "Shadow Credentials" 3 section: "Windows" 4 sectionSlug: "windows-hardening" 5 sourcePath: "src/windows-hardening/active-directory-methodology/acl-persistence-abuse/shadow-credentials.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/windows-hardening/active-directory-methodology/acl-persistence-abuse/shadow-credentials.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # Shadow Credentials 14 15 ## Intro <a href="#3f17" id="3f17"></a> 16 17 **Check the original post for [all the information about this technique](https://posts.specterops.io/shadow-credentials-abusing-key-trust-account-mapping-for-takeover-8ee1a53566ab).**<sup>[[1]](#references)</sup> 18 19 In summary, control of a user's or computer's **`msDS-KeyCredentialLink`** can let an attacker add a key credential, authenticate as that object with PKINIT, and—when the KDC and account support the necessary flows—use the resulting ticket with `S4U2Self`/user-to-user to recover the object's NT hash.<sup>[[1]](#references)</sup> 20 21 In the post, a method is outlined for setting up **public-private key authentication credentials** to acquire a unique **Service Ticket** that includes the target's NTLM hash. This process involves the encrypted NTLM_SUPPLEMENTAL_CREDENTIAL within the Privilege Attribute Certificate (PAC), which can be decrypted.<sup>[[1]](#references)</sup> 22 23 ### Requirements 24 25 To apply this technique, certain conditions must be met:<sup>[[1]](#references)</sup> 26 27 - A minimum of one Windows Server 2016 Domain Controller is needed. 28 - The Domain Controller must have a server authentication digital certificate installed. 29 - The directory schema must contain `msDS-KeyCredentialLink`; a Windows Server 2016 or newer DC and a PKINIT-capable certificate on the KDC are the practical platform requirements described by the research. Verify the domain's schema/DC mix rather than assuming the domain functional-level label alone decides exploitability. 30 - An account with delegated rights to modify the msDS-KeyCredentialLink attribute of the target object is required. 31 32 ## Abuse 33 34 The abuse of Key Trust for computer objects encompasses steps beyond obtaining a Ticket Granting Ticket (TGT) and the NTLM hash. The options include:<sup>[[1]](#references)</sup> 35 36 1. Creating an **RC4 silver ticket** to act as privileged users on the intended host. 37 2. Using the TGT with **S4U2Self** for impersonation of **privileged users**, necessitating alterations to the Service Ticket to add a service class to the service name. 38 39 A significant advantage of Key Trust abuse is its limitation to the attacker-generated private key, avoiding delegation to potentially vulnerable accounts and not requiring the creation of a computer account, which could be challenging to remove.<sup>[[1]](#references)</sup> 40 41 ## Tools 42 43 ### [**Whisker**](https://github.com/eladshamir/Whisker) 44 45 Whisker uses DSInternals to manipulate `msDS-KeyCredentialLink` from C#. Whisker and its Python counterpart **pyWhisker** support adding, listing, removing, and clearing key credentials.<sup>[[2]](#references)[[4]](#references)</sup> 46 47 **Whisker** functions include: 48 49 - **Add**: Generates a key pair and adds a key credential. 50 - **List**: Displays all key credential entries. 51 - **Remove**: Deletes a specified key credential. 52 - **Clear**: Erases all key credentials, potentially disrupting legitimate WHfB usage. 53 54 ```bash 55 Whisker.exe add /target:computername$ /domain:constoso.local /dc:dc1.contoso.local /path:C:\path\to\file.pfx /password:P@ssword1 56 ``` 57 58 ### [pyWhisker](https://github.com/ShutdownRepo/pywhisker) 59 60 pyWhisker brings the workflow to **UNIX-like systems** with Impacket and PyDSInternals, including list/add/remove and JSON import/export operations.<sup>[[4]](#references)</sup> 61 62 ```bash 63 python3 pywhisker.py -d "domain.local" -u "user1" -p "complexpassword" --target "user2" --action "list" 64 ``` 65 66 ### [ShadowSpray](https://github.com/Dec0ne/ShadowSpray/) 67 68 ShadowSpray enumerates domain objects over which the operator has rights such as `GenericWrite`/`GenericAll`, attempts to add key credentials broadly, and includes cleanup/recursive modes. Broad spraying is disruptive and conspicuous; use explicit targets and retain each added DeviceID for precise removal.<sup>[[3]](#references)</sup> 69 70 ## References 71 72 - [1] [Shadow Credentials: Abusing Key Trust Account Mapping for Account Takeover](https://posts.specterops.io/shadow-credentials-abusing-key-trust-account-mapping-for-takeover-8ee1a53566ab) 73 - [2] [Whisker - Tool for taking over AD accounts by manipulating msDS-KeyCredentialLink](https://github.com/eladshamir/Whisker) 74 - [3] [ShadowSpray - Tool to spray Shadow Credentials across a domain](https://github.com/Dec0ne/ShadowSpray/) 75 - [4] [pywhisker - Python version of the Shadow Credentials tool](https://github.com/ShutdownRepo/pywhisker)