skeleton-key.md (4513B)
1 --- 2 title: "Skeleton Key" 3 section: "Windows" 4 sectionSlug: "windows-hardening" 5 sourcePath: "src/windows-hardening/active-directory-methodology/skeleton-key.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/windows-hardening/active-directory-methodology/skeleton-key.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # Skeleton Key 14 15 ## Skeleton Key Attack 16 17 The **Skeleton Key attack** is a technique that allows attackers to **bypass Active Directory authentication** by **injecting a master password** into the LSASS process of each domain controller. After injection, the master password (default **`mimikatz`**) can be used to authenticate as **any domain user** while their real passwords still work.<sup>[[1]](#references)[[2]](#references)</sup> 18 19 Key facts: 20 21 - Requires **Domain Admin/SYSTEM + SeDebugPrivilege** on every DC and must be **reapplied after each reboot**.<sup>[[2]](#references)</sup> 22 - The classic Mimikatz implementation patches **NTLM** and **Kerberos RC4 (etype 0x17)** validation paths; AES-only authentication does **not accept that skeleton password through the RC4 hook**.<sup>[[2]](#references)</sup> 23 - Can conflict with third‑party LSA authentication packages or additional smart‑card / MFA providers.<sup>[[2]](#references)</sup> 24 - The Mimikatz module accepts the optional switch `/letaes` to avoid touching Kerberos/AES hooks in case of compatibility issues.<sup>[[3]](#references)</sup> 25 26 ### Execution 27 28 Classic, non‑PPL protected LSASS: 29 30 ```text 31 mimikatz # privilege::debug 32 mimikatz # misc::skeleton 33 ``` 34 35 If **LSASS is running as a protected process light (PPL)**, user-mode debug access is blocked. The historical Mimikatz procedure below loads its kernel driver and removes protection before patching LSASS. Credential Guard is a separate isolation control and should not be used as a synonym for PPL.<sup>[[3]](#references)[[4]](#references)</sup> 36 37 ```text 38 mimikatz # privilege::debug 39 mimikatz # !+ 40 mimikatz # !processprotect /process:lsass.exe /remove # drop PPL 41 mimikatz # misc::skeleton # inject master password 'mimikatz' 42 ``` 43 44 After injection, authenticate with any domain account but use password `mimikatz` (or the value set by the operator). Remember to repeat on **all DCs** in multi‑DC environments. 45 46 ## Mitigations 47 48 - **Log monitoring** 49 - System **Event ID 7045** (service/driver install) for unsigned drivers such as `mimidrv.sys`. 50 - **Sysmon**: Event ID 7 (driver load) for `mimidrv.sys`; Event ID 10 for suspicious access to `lsass.exe` from non‑system processes. 51 - Security **Event ID 4673/4611** for sensitive privilege use or LSA authentication package registration anomalies; correlate with unexpected 4624 logons using RC4 (etype 0x17) from DCs. 52 - **Hardening LSASS** 53 - Keep **RunAsPPL** and **Credential Guard** enabled where supported. They provide different protections, and together raise the cost and telemetry of attempts to modify or extract LSASS secrets.<sup>[[4]](#references)</sup> 54 - Disable legacy **RC4** where possible; Kerberos tickets limited to AES prevent the RC4 hook path used by the skeleton key.<sup>[[2]](#references)</sup> 55 - Quick PowerShell hunts: 56 - Detect unsigned kernel driver installs: `Get-WinEvent -FilterHashtable @{Logname='System';ID=7045} | ?{$_.message -like "*Kernel Mode Driver*"}` 57 - Hunt for Mimikatz driver: `Get-WinEvent -FilterHashtable @{Logname='System';ID=7045} | ?{$_.message -like "*Kernel Mode Driver*" -and $_.message -like "*mimidrv*"}` 58 - Validate PPL is enforced after reboot: `Get-WinEvent -FilterHashtable @{Logname='System';ID=12} | ?{$_.message -like "*protected process*"}` 59 60 For additional credential‑hardening guidance check [Windows credentials protections](/hacktricks/windows-hardening/stealing-credentials/credentials-protections). 61 62 ## References 63 64 - [1] [Netwrix – Skeleton Key attack in Active Directory (2022)](https://blog.netwrix.com/2022/11/29/skeleton-key-attack-active-directory/) 65 - [2] [TheHacker.recipes – Skeleton key (2026)](https://www.thehacker.recipes/ad/persistence/skeleton-key/) 66 - [3] [TheHacker.Tools – Mimikatz misc::skeleton module](https://tools.thehacker.recipes/mimikatz/modules/misc/skeleton) 67 - [4] [Microsoft Learn — Configure added LSA protection](https://learn.microsoft.com/en-us/windows-server/security/credentials-protection-and-management/configuring-additional-lsa-protection)