daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

shadow-credentials.md (4919B)


      1 ---
      2 title: "Shadow Credentials"
      3 section: "Windows"
      4 sectionSlug: "windows-hardening"
      5 sourcePath: "src/windows-hardening/active-directory-methodology/acl-persistence-abuse/shadow-credentials.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/windows-hardening/active-directory-methodology/acl-persistence-abuse/shadow-credentials.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # Shadow Credentials
     14 
     15 ## Intro <a href="#3f17" id="3f17"></a>
     16 
     17 **Check the original post for [all the information about this technique](https://posts.specterops.io/shadow-credentials-abusing-key-trust-account-mapping-for-takeover-8ee1a53566ab).**<sup>[[1]](#references)</sup>
     18 
     19 In summary, control of a user's or computer's **`msDS-KeyCredentialLink`** can let an attacker add a key credential, authenticate as that object with PKINIT, and—when the KDC and account support the necessary flows—use the resulting ticket with `S4U2Self`/user-to-user to recover the object's NT hash.<sup>[[1]](#references)</sup>
     20 
     21 In the post, a method is outlined for setting up **public-private key authentication credentials** to acquire a unique **Service Ticket** that includes the target's NTLM hash. This process involves the encrypted NTLM_SUPPLEMENTAL_CREDENTIAL within the Privilege Attribute Certificate (PAC), which can be decrypted.<sup>[[1]](#references)</sup>
     22 
     23 ### Requirements
     24 
     25 To apply this technique, certain conditions must be met:<sup>[[1]](#references)</sup>
     26 
     27 - A minimum of one Windows Server 2016 Domain Controller is needed.
     28 - The Domain Controller must have a server authentication digital certificate installed.
     29 - The directory schema must contain `msDS-KeyCredentialLink`; a Windows Server 2016 or newer DC and a PKINIT-capable certificate on the KDC are the practical platform requirements described by the research. Verify the domain's schema/DC mix rather than assuming the domain functional-level label alone decides exploitability.
     30 - An account with delegated rights to modify the msDS-KeyCredentialLink attribute of the target object is required.
     31 
     32 ## Abuse
     33 
     34 The abuse of Key Trust for computer objects encompasses steps beyond obtaining a Ticket Granting Ticket (TGT) and the NTLM hash. The options include:<sup>[[1]](#references)</sup>
     35 
     36 1. Creating an **RC4 silver ticket** to act as privileged users on the intended host.
     37 2. Using the TGT with **S4U2Self** for impersonation of **privileged users**, necessitating alterations to the Service Ticket to add a service class to the service name.
     38 
     39 A significant advantage of Key Trust abuse is its limitation to the attacker-generated private key, avoiding delegation to potentially vulnerable accounts and not requiring the creation of a computer account, which could be challenging to remove.<sup>[[1]](#references)</sup>
     40 
     41 ## Tools
     42 
     43 ### [**Whisker**](https://github.com/eladshamir/Whisker)
     44 
     45 Whisker uses DSInternals to manipulate `msDS-KeyCredentialLink` from C#. Whisker and its Python counterpart **pyWhisker** support adding, listing, removing, and clearing key credentials.<sup>[[2]](#references)[[4]](#references)</sup>
     46 
     47 **Whisker** functions include:
     48 
     49 - **Add**: Generates a key pair and adds a key credential.
     50 - **List**: Displays all key credential entries.
     51 - **Remove**: Deletes a specified key credential.
     52 - **Clear**: Erases all key credentials, potentially disrupting legitimate WHfB usage.
     53 
     54 ```bash
     55 Whisker.exe add /target:computername$ /domain:constoso.local /dc:dc1.contoso.local /path:C:\path\to\file.pfx /password:P@ssword1
     56 ```
     57 
     58 ### [pyWhisker](https://github.com/ShutdownRepo/pywhisker)
     59 
     60 pyWhisker brings the workflow to **UNIX-like systems** with Impacket and PyDSInternals, including list/add/remove and JSON import/export operations.<sup>[[4]](#references)</sup>
     61 
     62 ```bash
     63 python3 pywhisker.py -d "domain.local" -u "user1" -p "complexpassword" --target "user2" --action "list"
     64 ```
     65 
     66 ### [ShadowSpray](https://github.com/Dec0ne/ShadowSpray/)
     67 
     68 ShadowSpray enumerates domain objects over which the operator has rights such as `GenericWrite`/`GenericAll`, attempts to add key credentials broadly, and includes cleanup/recursive modes. Broad spraying is disruptive and conspicuous; use explicit targets and retain each added DeviceID for precise removal.<sup>[[3]](#references)</sup>
     69 
     70 ## References
     71 
     72 - [1] [Shadow Credentials: Abusing Key Trust Account Mapping for Account Takeover](https://posts.specterops.io/shadow-credentials-abusing-key-trust-account-mapping-for-takeover-8ee1a53566ab)
     73 - [2] [Whisker - Tool for taking over AD accounts by manipulating msDS-KeyCredentialLink](https://github.com/eladshamir/Whisker)
     74 - [3] [ShadowSpray - Tool to spray Shadow Credentials across a domain](https://github.com/Dec0ne/ShadowSpray/)
     75 - [4] [pywhisker - Python version of the Shadow Credentials tool](https://github.com/ShutdownRepo/pywhisker)