daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

skeleton-key.md (4513B)


      1 ---
      2 title: "Skeleton Key"
      3 section: "Windows"
      4 sectionSlug: "windows-hardening"
      5 sourcePath: "src/windows-hardening/active-directory-methodology/skeleton-key.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/windows-hardening/active-directory-methodology/skeleton-key.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # Skeleton Key
     14 
     15 ## Skeleton Key Attack
     16 
     17 The **Skeleton Key attack** is a technique that allows attackers to **bypass Active Directory authentication** by **injecting a master password** into the LSASS process of each domain controller. After injection, the master password (default **`mimikatz`**) can be used to authenticate as **any domain user** while their real passwords still work.<sup>[[1]](#references)[[2]](#references)</sup>
     18 
     19 Key facts:
     20 
     21 - Requires **Domain Admin/SYSTEM + SeDebugPrivilege** on every DC and must be **reapplied after each reboot**.<sup>[[2]](#references)</sup>
     22 - The classic Mimikatz implementation patches **NTLM** and **Kerberos RC4 (etype 0x17)** validation paths; AES-only authentication does **not accept that skeleton password through the RC4 hook**.<sup>[[2]](#references)</sup>
     23 - Can conflict with third‑party LSA authentication packages or additional smart‑card / MFA providers.<sup>[[2]](#references)</sup>
     24 - The Mimikatz module accepts the optional switch `/letaes` to avoid touching Kerberos/AES hooks in case of compatibility issues.<sup>[[3]](#references)</sup>
     25 
     26 ### Execution
     27 
     28 Classic, non‑PPL protected LSASS:
     29 
     30 ```text
     31 mimikatz # privilege::debug
     32 mimikatz # misc::skeleton
     33 ```
     34 
     35 If **LSASS is running as a protected process light (PPL)**, user-mode debug access is blocked. The historical Mimikatz procedure below loads its kernel driver and removes protection before patching LSASS. Credential Guard is a separate isolation control and should not be used as a synonym for PPL.<sup>[[3]](#references)[[4]](#references)</sup>
     36 
     37 ```text
     38 mimikatz # privilege::debug
     39 mimikatz # !+
     40 mimikatz # !processprotect /process:lsass.exe /remove   # drop PPL
     41 mimikatz # misc::skeleton                               # inject master password 'mimikatz'
     42 ```
     43 
     44 After injection, authenticate with any domain account but use password `mimikatz` (or the value set by the operator). Remember to repeat on **all DCs** in multi‑DC environments.
     45 
     46 ## Mitigations
     47 
     48 - **Log monitoring**
     49   - System **Event ID 7045** (service/driver install) for unsigned drivers such as `mimidrv.sys`.
     50   - **Sysmon**: Event ID 7 (driver load) for `mimidrv.sys`; Event ID 10 for suspicious access to `lsass.exe` from non‑system processes.
     51   - Security **Event ID 4673/4611** for sensitive privilege use or LSA authentication package registration anomalies; correlate with unexpected 4624 logons using RC4 (etype 0x17) from DCs.
     52 - **Hardening LSASS**
     53   - Keep **RunAsPPL** and **Credential Guard** enabled where supported. They provide different protections, and together raise the cost and telemetry of attempts to modify or extract LSASS secrets.<sup>[[4]](#references)</sup>
     54   - Disable legacy **RC4** where possible; Kerberos tickets limited to AES prevent the RC4 hook path used by the skeleton key.<sup>[[2]](#references)</sup>
     55 - Quick PowerShell hunts:
     56   - Detect unsigned kernel driver installs: `Get-WinEvent -FilterHashtable @{Logname='System';ID=7045} | ?{$_.message -like "*Kernel Mode Driver*"}`
     57   - Hunt for Mimikatz driver: `Get-WinEvent -FilterHashtable @{Logname='System';ID=7045} | ?{$_.message -like "*Kernel Mode Driver*" -and $_.message -like "*mimidrv*"}`
     58   - Validate PPL is enforced after reboot: `Get-WinEvent -FilterHashtable @{Logname='System';ID=12} | ?{$_.message -like "*protected process*"}`
     59 
     60 For additional credential‑hardening guidance check [Windows credentials protections](/hacktricks/windows-hardening/stealing-credentials/credentials-protections).
     61 
     62 ## References
     63 
     64 - [1] [Netwrix – Skeleton Key attack in Active Directory (2022)](https://blog.netwrix.com/2022/11/29/skeleton-key-attack-active-directory/)
     65 - [2] [TheHacker.recipes – Skeleton key (2026)](https://www.thehacker.recipes/ad/persistence/skeleton-key/)
     66 - [3] [TheHacker.Tools – Mimikatz misc::skeleton module](https://tools.thehacker.recipes/mimikatz/modules/misc/skeleton)
     67 - [4] [Microsoft Learn — Configure added LSA protection](https://learn.microsoft.com/en-us/windows-server/security/credentials-protection-and-management/configuring-additional-lsa-protection)